Product help
Connect Microsoft 365 without handing Domain Signals a user account.
M365 Signals uses tenant-wide administrator consent for separately scoped, read-only Microsoft Graph applications. Collection runs app-only in the background; Microsoft access tokens, user refresh tokens and content never reach the browser or become part of a report.
Bounded collection. Explicit permission. No exploitation or authentication attempts.
What to do
Connect, assess, monitor and disconnect Microsoft 365 safely
Each guide takes you from the current screen or state to one safe, testable outcome. This page helps you connect, assess, monitor and disconnect Microsoft 365 safely. The relevant evidence, owner and limit remain available from the same route.
Useful for: Microsoft 365 administrator · workspace owner · security reviewer.
M365 Signals operating guide
Consent, evidence and recovery in plain English
In practice
Complete the task safely
Where to start
Begin here when you need to connect, assess, monitor and disconnect Microsoft 365 safely. Stay with the domain, relationship or service state named on the page; the task does not widen silently into a different security or product claim.
What to check
The M365 Signals Grade is independent from the external Domain Signals grade and records evidence coverage, policy version and Microsoft observation time. Open the relevant report evidence when you need to verify the source, observation time, attribution or qualification behind it.
How to complete the task
Complete the step shown on the page, then check the resulting state before moving on. Unknown, unavailable and not-applicable outcomes remain distinct, so absence is never presented as a successful or reassuring result.
How to recover safely
Contact support with the correlation reference, never credentials or secret values. Record the resulting owner, evidence or recovery state where the product provides it, so another person can verify what happened without repeating the task.
What you can rely on
Checks that prevent mistakes
Confirm the workspace, domain and evidence state before completing a task.
M365 Signals uses separately consented read-only Microsoft Graph applications and does not collect mailbox, message, Teams-chat, SharePoint-file or email content.
The M365 Signals Grade is independent from the external Domain Signals grade and records evidence coverage, policy version and Microsoft observation time.
Microsoft Secure Score is displayed as Microsoft-supplied context and its raw percentage does not directly determine the M365 Signals Grade.
Important boundary
What this does not mean
Use M365 Signals supports one defined outcome: connect, assess, monitor and disconnect Microsoft 365 safely. Domain Signals is not a penetration test, certification, data-residency assessment or prediction of breach likelihood. Missing evidence is not evidence of safety.
Questions answered
Read the conclusion and its limits together
What does Use M365 Signals help me decide?
This page helps you connect, assess, monitor and disconnect Microsoft 365 safely.
What evidence sits behind the answer?
Domain Signals keeps the source, observation time and evidence state alongside each conclusion. The relevant report view provides the technical detail when you need to inspect it.
What should I not conclude?
Use M365 Signals supports one defined outcome: connect, assess, monitor and disconnect Microsoft 365 safely. Domain Signals is not a penetration test, certification, data-residency assessment or prediction of breach likelihood. Missing evidence is not evidence of safety.
Keep exploring