Connect Microsoft 365
Connecting your M365 tenant is the first step to using Calibrant. This grants read-only access to your organization's directory via the Microsoft Graph API.
Prerequisites
- A Microsoft 365 tenant with an active subscription
- Global Administrator or Application Administrator role in Entra ID
- A Calibrant account — sign up here
Connect your tenant
- Sign in to Calibrant and navigate to Connections in the sidebar.
- Click the Connect button on the Microsoft 365 card.
- You'll be redirected to Microsoft's login page — sign in with your admin account.
- Review the permissions and click Accept to grant admin consent.
- You'll be redirected back to Calibrant with a success banner.
What permissions are requested? Calibrant requests read-only directory access:
Organization.Read.All, User.Read.All, and Directory.Read.All. No write permissions are requested at connection time.After connecting
The Connections page will show your tenant name, status, and connection date. You can now register agents for optimization.
Power Platform permission (for Enterprise relay)
If you are using the Calibrant Relay with Microsoft-authenticated Copilot Studio agents, you need to grant an additional permission so personas can authenticate with Power Platform. This is a one-time admin step.
- Go to portal.azure.com → Entra ID → App registrations → find Calibrant.AI
- Click API permissions → Add a permission
- Click APIs my organization uses and search for
PowerApps Service - Select Delegated permissions → tick CopilotStudio.Copilots.Invoke ("Allows Invoking Copilots") → click Add permissions
- Click Grant admin consent for [your tenant]
After adding this permission, re-authenticate any existing personas in Connections → Test Personas using the Re-auth button. The new permission will be included in the fresh device code flow.
Revoking access
- Go to Entra ID → Enterprise applications.
- Find Calibrant and remove the consent.
- Optionally, delete the connection from Calibrant's Connections page.