Connect Microsoft 365 (optional)
Two Microsoft touchpoints, two jobs
Calibrant touches your Microsoft tenant in two separate ways, and they do not overlap:
- The relay scans. It runs in your Azure subscription with its own Managed Identity and the Graph application roles you assign to it. Every tenant read for Healthcheck and Security Baseline happens there. Calibrant never holds a Microsoft token for it.
- Connecting Microsoft 365 records identity. It is a one-time, delegated sign-in by one of your administrators. Calibrant reads a single record about your organisation, discards the token, and keeps three values: the organisation's display name, its directory (tenant) ID, and the list of domains it has verified. It grants the relay nothing, is never used to scan, and can be completed before any relay exists.
Why connect at all?
To put the tenant you intend to audit on record. A relay is deployed into your Azure subscription with its own Managed Identity, and nothing about that identity names an organisation. The recorded name and directory ID state which tenant this workspace is for, so you can check them against the directory your relay's Managed Identity belongs to. Calibrant does not automate that comparison yet.
To invite teammates from every domain your organisation uses. Team invitations are domain-checked. Without this connection, Calibrant only knows the domain you signed up with; with it, the verified-domain list lets your owners and admins invite colleagues from any domain the organisation has verified in Microsoft 365. Because no relay is needed, this works on day one.
It also replaces “Microsoft 365 Tenant” with your real organisation name throughout the dashboard and printable reports.
Calibrant makes exactly one Graph call during this flow —GET /v1.0/organization — and then discards the access token. The verified-domain list is part of that same response; no additional permission or call is needed for it. No Microsoft token is stored, and no refresh token is requested.
Prerequisites
- A Microsoft 365 commercial cloud tenant with an active subscription. Microsoft 365 GCC, GCC High, DoD, China/21Vianet, and every other sovereign or national cloud are not supported.
- Global Administrator or Application Administrator role in Entra ID
- A Calibrant account with the owner or admin role — sign up here
Connect your tenant
- Sign in to Calibrant and navigate to Connections in the sidebar.
- Click the Connect button on the Microsoft 365 card.
- Read the connection authorization, which states exactly what this flow reads and keeps, and accept it.
- You'll be redirected to Microsoft's login page — sign in with your admin account.
- Review the permissions and click Accept to grant admin consent.
- You'll be redirected back to Calibrant with a success banner.
User.Read and Organization.Read.All. Nothing else — noDirectory.Read.All, no write permissions, and no offline_access, so Calibrant cannot hold durable access to your tenant through this connection.After connecting
The Connections page shows your tenant name, the connection date, and how many verified domains were recorded. Settings → Team lists every domain you can invite teammates from. If you have not deployed a relay yet, that is the next step: deploy the Calibrant Relay so scans can run against your tenant. Connecting does not replace the relay, and the relay does not replace connecting.
Keeping the domain list current
Calibrant keeps no token, so it cannot re-read your organisation on its own. After you add or remove a verified domain in Microsoft 365, click Refresh identityon the Connections page. It runs the same one-time sign-in and replaces the recorded list.
If the domains were not adopted
The recorded domain list widens who can be invited into your workspace, so Calibrant adopts it only when the organisation you signed in to is demonstrably yours: at least one domain the workspace already trusts (any domain listed under Settings → Team, or the domain of the administrator connecting) must be among the verified domains. If an administrator signs in to an unrelated Microsoft tenant, the tenant identity is still recorded but the domain list is not, and the Connections page says so. Reconnect with an account from your own organisation to detect them.
Revoking access
- Go to Entra ID → Enterprise applications.
- Find Calibrant and remove the consent.
Removing consent stops any future sign-in through this connection. Calibrant holds no token to revoke. The recorded name, directory ID and domain list stay with your workspace until the workspace is deleted, and you can replace the list at any time with Refresh identity.