Solution

Read-only Microsoft Graph integration

Connect customer Microsoft 365 tenants through read-only Microsoft Graph delegated access. Assessment data flows into customer workspaces without write permissions to tenant configuration.

Integration model

Delegated access

Read-only permissions scoped to assessment needs.

Per-customer consent

Each customer workspace has its own Graph connection.

Posture data sync

Secure Score, identity, Defender, and related signals.

No write access

Platform does not modify customer tenant settings.

Connection workflow

Initiate from customer workspace

An organization member with appropriate permissions starts the Graph consent flow for the customer.

Admin consent

Customer tenant administrator approves read-only delegated permissions.

First sync

Initial assessment runs after connection to populate posture data and findings.

Security properties

Least privilege
Only required Graph scopes for posture assessment.
Token storage
Credentials stored securely for ongoing assessment.
Organization isolation
Each MSP organization manages its own customer connections.
Activity log
Connection and sync events recorded in the activity log.

Related pages

Frequently asked questions

Next steps

See Microsoft Graph integration in a demo

Microsoft Graph MSP Integration | SecurityScore.me