Skip to main content

Product help

Connect Microsoft 365 without handing Domain Signals a user account.

M365 Signals uses tenant-wide administrator consent for separately scoped, read-only Microsoft Graph applications. Collection runs app-only in the background; Microsoft access tokens, user refresh tokens and content never reach the browser or become part of a report.

Bounded collection. Explicit permission. No exploitation or authentication attempts.

What to do

Connect, assess, monitor and disconnect Microsoft 365 safely

Each guide takes you from the current screen or state to one safe, testable outcome. This page helps you connect, assess, monitor and disconnect Microsoft 365 safely. The relevant evidence, owner and limit remain available from the same route.

Useful for: Microsoft 365 administrator · workspace owner · security reviewer.

M365 Signals operating guide

Consent, evidence and recovery in plain English

Before you connectM365 Signals is a separately entitled pilot. The workspace needs a non-archived, ownership-verified primary Domain Signals domain that is also verified in the Microsoft 365 tenant. Commercial Microsoft 365 tenants are supported; sovereign Microsoft clouds are not included in this release.
Administrator consentA Microsoft administrator approves a dedicated read-only application for the tenant. The consent link is single-use and expires after 15 minutes. It grants no Domain Signals account access. Microsoft may display an unverified-publisher warning during the controlled pilot; general availability remains blocked until publisher verification is visibly confirmed.
What core access readsCore coverage reads organisation and verified-domain details, authentication-method policy and summaries, Conditional Access policies, directory roles, enterprise applications, consent grants and Microsoft Secure Score through Microsoft Graph v1.0. Optional identity and device packs require separate consent and suitable Microsoft licensing.
What is not collectedDomain Signals does not collect mailbox or email content, Teams chats, files, SharePoint content, user refresh tokens, device names or serial numbers. Raw Microsoft Graph responses are validated and reduced to the evidence needed for the assessment rather than retained as a content archive.
Grade and Microsoft Secure ScoreThe M365 Signals Grade is independent from the external Domain Signals grade. Evidence confidence and critical unknowns can cap or prevent a grade. Microsoft Secure Score is displayed separately as Microsoft-supplied context; its raw percentage does not directly determine the M365 Signals Grade.
Licensing and unavailable evidenceMicrosoft licensing and consent determine which evidence can be observed. Unsupported or unavailable evidence is labelled unknown or unavailable and is never counted as a pass. A changed permission pack or coverage profile creates a visible break in grade comparability.
Monitoring and freshnessWhen enabled, a lightweight connection and critical-control check runs every four hours and a sealed assessment runs every 24 hours. Partial Microsoft responses, throttling and provider outages affect evidence health rather than creating a false customer finding. Evidence older than 72 hours is shown as stale.
Disconnect and recoveryDisconnect requires a recent authenticator check and typed confirmation. It stops future collection while retaining sealed reports for the applicable plan retention period. A Microsoft administrator separately removes the Enterprise Application in Entra. If consent expires, permissions change or validation fails, use the single recovery action shown in the M365 card or contact support with the correlation reference.

In practice

Complete the task safely

01

Where to start

Begin here when you need to connect, assess, monitor and disconnect Microsoft 365 safely. Stay with the domain, relationship or service state named on the page; the task does not widen silently into a different security or product claim.

02

What to check

The M365 Signals Grade is independent from the external Domain Signals grade and records evidence coverage, policy version and Microsoft observation time. Open the relevant report evidence when you need to verify the source, observation time, attribution or qualification behind it.

03

How to complete the task

Complete the step shown on the page, then check the resulting state before moving on. Unknown, unavailable and not-applicable outcomes remain distinct, so absence is never presented as a successful or reassuring result.

04

How to recover safely

Contact support with the correlation reference, never credentials or secret values. Record the resulting owner, evidence or recovery state where the product provides it, so another person can verify what happened without repeating the task.

What you can rely on

Checks that prevent mistakes

Confirm the workspace, domain and evidence state before completing a task.

Clear scope

M365 Signals uses separately consented read-only Microsoft Graph applications and does not collect mailbox, message, Teams-chat, SharePoint-file or email content.

Traceable evidence

The M365 Signals Grade is independent from the external Domain Signals grade and records evidence coverage, policy version and Microsoft observation time.

Honest limits

Microsoft Secure Score is displayed as Microsoft-supplied context and its raw percentage does not directly determine the M365 Signals Grade.

Important boundary

What this does not mean

Use M365 Signals supports one defined outcome: connect, assess, monitor and disconnect Microsoft 365 safely. Domain Signals is not a penetration test, certification, data-residency assessment or prediction of breach likelihood. Missing evidence is not evidence of safety.

Questions answered

Read the conclusion and its limits together

What does Use M365 Signals help me decide?

This page helps you connect, assess, monitor and disconnect Microsoft 365 safely.

What evidence sits behind the answer?

Domain Signals keeps the source, observation time and evidence state alongside each conclusion. The relevant report view provides the technical detail when you need to inspect it.

What should I not conclude?

Use M365 Signals supports one defined outcome: connect, assess, monitor and disconnect Microsoft 365 safely. Domain Signals is not a penetration test, certification, data-residency assessment or prediction of breach likelihood. Missing evidence is not evidence of safety.

Keep exploring

Useful next steps

The next responsible step

Open product support

Open product support