Skip to main content
The Company M365 Setup page lets you connect each of your client companies to their Microsoft 365 tenant in one place. Once connected, MSPortal automatically syncs users, licenses, domains, and Secure Score data for that company.

Prerequisites

  • Use an MSP staff account with permission to manage companies or integration company mappings; opening Settings alone does not grant connection rights
  • An administrator from each client’s Microsoft 365 tenant must be available to approve permissions (or you must have admin credentials for their tenant)

Connecting a Company

1

Navigate to the M365 Companies page

Go to Settings > Integrations > Microsoft 365 > Companies.You’ll see a list of all your companies with their current connection status. A progress bar at the top shows how many companies are connected out of your total.
2

Click Connect

Find the company you want to connect and click the Connect button on its row.A popup window will open with the Microsoft sign-in page.
3

Authenticate and grant permissions

Sign in with an administrator account from the client’s Microsoft 365 tenant and approve the requested permissions.Complete any integration compliance acknowledgment shown, then finish administrator consent. On success the popup closes and MSPortal refreshes the connection list. Check the company and Microsoft tenant before using synchronized data.
4

Repeat for each company

Work through the list, clicking Connect for each company you want to connect. Use the search bar to quickly find specific companies.
If your browser blocks the popup, you’ll see an error message. Allow popups for MSPortal and try again.
If you sign into client Microsoft 365 tenants using a separate browser profile, a different browser, or need to send the authentication link to someone else, use the Generate Link option instead.
1

Click Generate Link

Open the company row’s Actions menu and choose Generate link. A shareable authentication URL appears in a dialog. MSPortal attempts to copy it; if browser clipboard access is denied, copy the displayed link manually.
2

Open the link in your preferred browser

Paste the link into the browser or browser profile where you are signed into the client’s Microsoft 365 admin account, and complete the authentication flow.
Each generated link expires in 7 days and can only be used once. If the link expires or has already been used, click Generate new link to create a fresh one.
The Generate Link option is especially useful if you use tools like Chrome profiles or Firefox containers to manage multiple Microsoft 365 tenants. Generate the link in MSPortal, then paste it into the correct browser profile to authenticate.

Reading the companies table

The table lists one row per Microsoft tenant connection. A company with several connected tenants appears several times; use Actions > Add tenant to add another connection and Reconnect to renew the selected one. Connected identifies a saved connection. It does not prove a successful current sync. Last synced reflects the latest user or group sync, not every Microsoft dataset; inspect the relevant Cloud page for the data you need. For an unconnected company that does not use Microsoft 365, choose Actions > Not applicable. This saves immediately and removes it from the setup-progress denominator. Use Restore to put it back. This is a setup classification, not a Microsoft consent-revocation control.

Reconnecting a Company

If a company’s Microsoft 365 connection needs to be refreshed (e.g., after a token expiry or permission change), click the Reconnect button on the company’s row. This follows the same authentication flow as the initial connection.

Disconnecting a tenant

Open Actions > Disconnect on the intended tenant row. Review the company and domain in the confirmation and confirm only when you intend to remove that connection. Other tenant connections for the company are separate. Do not assume reconnecting restores every prior imported record or that removing the portal connection revokes all Microsoft-side consent.

Questions and troubleshooting

Each connected Microsoft tenant gets its own row. Use its domain and tenant ID to distinguish connections before reconnecting or disconnecting.
No. It counts applicable companies with connections. Excluded companies do not count toward the denominator, and one company with multiple tenants still counts as one connected company.
No. Check that the expected tenant appears after the list refreshes. If consent was canceled or failed, correct the reported issue and start again.
No. The companies table uses the latest user or group synchronization time. Check the relevant dataset and its timestamp before reporting on licenses, domains or posture.
Find the company using the Not applicable status filter and choose Restore. Both classification changes save immediately; neither is a replacement for disconnecting a tenant.