The Entra ID integration covers who can sign in; the Microsoft 365 integration covers what happens after: sharing settings, mailbox rules, and tenant configuration, the surface where data actually leaves organizations. Together they turn most of your Microsoft-stack controls into continuously verified checks.
Prerequisites
- An OptiTech workspace with the Admin or Owner role.
- Global Administrator in your Microsoft tenant for admin consent.
- The Entra ID integration connected first, since Microsoft 365 checks reference the same tenant.
Connect the integration
- In the OptiTech Console, go to Integrations and select Microsoft 365.
- Click Connect and grant admin consent for the read-only permission set.
- Choose which workloads are in scope: Exchange Online, SharePoint and OneDrive, and Teams settings.
- The first sync completes within minutes and the workload checks activate.
Checks the integration activates
- External sharing baseline: SharePoint and OneDrive sharing settings verified against your documented policy; a drift to "Anyone with the link" is a finding the day it happens.
- Mail forwarding rules: external auto-forwarding, the classic exfiltration and BEC signal, detected tenant-wide.
- Mailbox auditing: verified enabled for all mailboxes with the required retention.
- Legacy authentication: verified blocked, closing the MFA bypass path.
- Secure Score trend: recorded per sync, giving your board report a recognizable Microsoft metric.
Why this matters per framework
These checks feed cross-mapped controls: NIS2's basic hygiene measures, ISO 27001's information transfer and access controls, Cyber Essentials' secure configuration theme, and the data-handling sections of every customer questionnaire that asks "how do you prevent oversharing?"
Verify the connection
- Confirm Status: Connected with a recent sync on the integration page.
- Filter Controls by Source: Microsoft 365; each control shows its latest result and evidence trail.
- Deliberately relax a sharing setting in a test site and confirm a finding opens on the next sync, then revert it. The finding lifecycle is your rehearsal for the real thing.
Troubleshooting
- Workload shows no data: the corresponding admin center may need the service enabled, or consent was granted by a role that can't authorize that workload.
- Findings for settings you believe are correct: check whether a per-site override diverges from the tenant default; the finding lists the specific site.
- Duplicate identity findings: identity checks belong to the Entra ID integration; disable overlapping checks in whichever integration you don't want to own them.
Need help?
Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.