Microsoft 365 Agent
Microsoft 365 in Switchboard. Review AI skills, playbooks, access limits and setup requirements before connecting your MSP systems.
How the Microsoft 365 integration works
Microsoft 365 is where most of your clients' identity already lives, and it is where the questions that matter get asked: who is missing MFA, which paid seats nobody uses, which laptops fell out of compliance, what Conditional Access really covers, which apps somebody consented to last quarter. Connect each tenant and a session answers those across all of them at once. Consent is per tenant and per capability pack, granted by the client's own Global Admin — reads are the base, and user, licensing and device changes are deliberate additions on top. Switchboard connects through an MSPStuff-hosted MCP server, so there's nothing to install and no API keys to hand your techs.
Hosted and external AI connections provide read-only access. Guidance, shared playbooks and automations we release for everyone are included with Dedicated. Bespoke automation builds are scoped separately. Any change a platform could make is held back — refused by our server before anything reaches the platform — until a person switches it on, and nothing is switched on today. Vendor consent does not switch any change on.
| License | Unused seats |
|---|---|
| Business Premium | 12 of 60 |
| Business Standard | 6 of 40 |
| Exchange Online | 3 of 25 |
Read-only today. Any change the integration could make in Microsoft 365 is held back — refused by our server before anything reaches Microsoft 365 — until a person switches it on, and nothing is switched on today. A client's consent to a capability pack does not switch anything on; the packs are a second fence beneath that refusal — each is consented by the client's own Global Admin, tenant by tenant, and a pack that was never consented has no token minted for it. Held back behind the user-and-group manage pack: a session could create an account and hand back a one-time temp password, edit display name, job title, department and usage location, disable and re-enable sign-in, reset a password, revoke every refresh token a person holds, clear their registered phone and Microsoft Authenticator methods, create a security group, and add or remove group members. Behind the licensing pack: assigning and removing SKUs on a user, and nothing else — no subscription is bought, cancelled or resized. Behind the device-manage pack: a sync, a reboot, or a remote lock. Two destructive tiers stand on their own and are granted separately from all of that: user delete and restore, where a delete drops the account into Microsoft's 30-day recycle bin, and device wipe and retire. Even once switched on, every destructive call would be refused unless the exact target is echoed back — the account's sign-in address, the deleted object's id, or the device's exact name.
What it can do
- Users & sign-inThe people in a tenant: search and read them, see their licenses, their groups, and whether they're synced from on-prem AD — plus the whole lifecycle sequence behind an onboard, a password reset, or an offboard.4skills
Directory identity only — no mailbox, file, Teams message or SharePoint document is readable or writable from here. Temp passwords are shown once and cannot be retrieved afterwards. It edits the four profile fields named above and no others: it does not set a manager, change a sign-in address, or grant an admin role. Clearing MFA methods removes phone and Authenticator registrations and leaves the password method alone.
Writes: With the user-and-group manage pack granted: creates an account and returns a one-time temporary password that must be changed at first sign-in; edits display name, job title, department and usage location; disables and re-enables sign-in; resets a password to a fresh one-time value; revokes every refresh token so all of a person's sessions must re-authenticate; and deletes their registered phone and Microsoft Authenticator methods, forcing MFA re-registration. With the user destructive pack granted: deletes an account into Microsoft's 30-day recycle bin, or restores one out of it — both refused unless the exact confirm string is echoed back, the account's sign-in address to delete and the deleted object's id to restore.
- Find a person in a client tenant from a fragment of their display name or their sign-in address.
- Open one account in full — job title, department, the licenses assigned to it, whether sign-in is enabled, and whether it's synced up from on-prem AD.
- Every group an account belongs to directly, security and Microsoft 365 alike — inherited nesting isn't flattened out.
- Walk a tenant's whole directory alphabetically, up to 500 at a time — the read for when you want everybody rather than one lookup.
- Groups & TeamsHow a tenant is organized: security, Microsoft 365 and dynamic groups with their membership, the tenant-wide rules new groups inherit, and the Teams and SharePoint inventory sitting on top of them.7skills
Group creation covers security groups only — Microsoft 365 groups, distribution lists and Teams cannot be created here, and no team, channel or SharePoint site is created, renamed or deleted. Dynamic membership rules are shown but never edited. The Teams and SharePoint reads are inventory: names, descriptions, visibility and URLs, never a message, a file, or a sharing permission.
Writes: With the user-and-group manage pack granted: creates a security group, and adds or removes one member of a group at a time.
- Every group in a tenant — security, Microsoft 365 and dynamic alike — with its mail state and, where one exists, the rule that decides membership.
- One group on its own, found either by object id or by its exact display name.
- Who sits directly inside a group, by name and sign-in address.
- The tenant-wide group rules — guest access, naming policy, and the defaults every new Microsoft 365 group inherits.
- Every team in the tenant with its description and its visibility — the collaboration inventory, not its contents.
- The channels inside one team, including standard and private ones, each with its name and membership type.
- Every SharePoint site in the tenant with its URL and creation date — where content lives, not what's in it.
- LicensingWhat the tenant is paying for and who's actually holding it: owned SKUs with the seat math worked out, one person's assignments, and the moves that free a seat up or fill one.2skills
It never buys, cancels or resizes a subscription; assignment only shuffles seats the client already pays for. The licensing pack carries the assignment permission alone and cannot read the SKU catalogue under its own token, so it resolves the SKU from the catalogue skill first or takes its GUID. Handed only a part number, it still tries the lookup, and if that comes back forbidden it falls through and sends the part number to Graph as though it were a SKU id — which Graph then rejects, so the failure surfaces at the assignment rather than at the lookup. A user also needs a usage location set before any license will attach to them.
Writes: With the licensing pack granted: assigns a SKU to a user and removes a SKU from a user. That changes who holds a seat — it does not change how many seats the client owns.
- Every SKU the tenant owns with the arithmetic already done — bought, consumed, and how many seats are sitting idle.
- What one person is licensed for, listed by SKU part number.
- Exchange & mailThe two mailbox-level reads that answer real tickets: how a mailbox is configured, and what rules are quietly running inside it.2skills
Settings and rules only. No message, attachment, calendar item or mailbox content is readable from here, and nothing in this area writes — a hostile forwarding rule gets reported to you, not removed by the session.
- One mailbox's configuration — out-of-office state and text, time zone, working hours, and how meeting invites are handled.
- The inbox rules on a mailbox, where the quiet forward-and-delete an intruder left behind is what you're looking for.
- Intune & devicesManaged hardware and the policy behind it: enrolled devices with compliance state and last check-in, the compliance, configuration and app-protection policies they're judged against, the published app catalogue — and the remote actions that follow a missing laptop.7skills
It acts on devices Intune already manages — it cannot enroll one, and it cannot create, edit or assign a compliance policy, configuration profile or app-protection policy; those four inventories are read-only and need the tenant to actually hold Intune licensing before they return anything. A device reports a compliance state, never a breakdown of which specific rule it tripped — the non-compliant list and the policy inventory are two separate reads that you line up yourself. There is no remote-control path here either: no screen, no shell, no file browsing.
Writes: With the device-manage pack granted: makes a device sync its Intune policy immediately, reboots it now, or remote-locks it. With the device-destructive pack granted: factory-wipes a device, which does not preserve user data though it can optionally leave enrollment intact, or retires it, which strips company data and management off and leaves the owner's personal data in place. Both destructive actions are refused until the device's exact name is echoed back.
- Every Intune-enrolled device in a tenant with its OS and version, model, assigned user, compliance state, and when it last checked in.
- A single managed device pulled up by its id or by its exact device name.
- Only the devices currently sitting outside compliance — the remediation list, without the healthy fleet wrapped around it.
- The compliance policies a tenant defines and who they're assigned to — the standard the fleet is being held to, read on its own rather than joined to any one device's verdict.
- What Intune is actually pushing at the fleet: the configuration profiles and the settings inside them.
- The app catalogue published through Intune, each with its publisher and the date it was added.
- App-protection (MAM) policies — the rules that follow company data onto phones nobody ever enrolled.
- Security & postureThe security review, on demand: MFA registration across the tenant and per person, who holds privileged roles, what Conditional Access and the tenant policies actually enforce, Secure Score, Identity Protection risk, and the app-and-consent inventory nobody has audited.13skills
Read-only throughout — this area reports posture, it never enforces it. No Conditional Access policy is created or switched on, no risky user is dismissed or remediated, no consent is revoked and no service principal is disabled. Some of it depends on what the client licenses from Microsoft rather than on this connection: Identity Protection risk needs Entra ID P2, and Conditional Access policies and named locations need P1 — without those, there is simply nothing for Microsoft to return.
- The whole tenant's MFA registration in one answer — how many people have it, who doesn't, and which of the people who don't are administrators.
- The authentication methods one named person has actually registered — the single-user version of that report.
- Who holds which privileged directory role, Global Admin included — the admin-access audit an MSP is expected to have on file.
- Every Conditional Access policy with its on/off/report-only state and its grant controls, so a coverage gap is visible without opening each one; the client needs Entra ID P1 for any of it to exist.
- The trusted IP ranges and country locations those policies point at — another P1 feature on the client's side.
- Which MFA methods the tenant permits at all — Authenticator, FIDO2, SMS and the rest — and how each one is configured.
- The tenant's default-permission posture: what an ordinary user may do, what guests can see, and whether people can consent to apps by themselves.
- Microsoft's own Secure Score for the tenant, current against maximum, together with the top improvement actions Microsoft publishes alongside it.
- The accounts Identity Protection currently rates as at risk, with the level attached — Entra ID P2 territory.
- The individual events behind those flags — detection type, level, IP, location and when each fired; also a P2 feature.
- Every service principal standing in the tenant — the inventory of what has been integrated, shadow IT very much included.
- The applications registered in the tenant itself, with their sign-in audience and creation date.
- Who consented to what: the delegated OAuth permission grants, which is where a malicious consent shows itself.
- Tenant, audit & service healthWhat the tenant is, what has been happening in it, and whether Microsoft's side is behaving: organization and domain facts, sign-in events, usage counts, service health, and the Message Center notices about what's changing next.7skills
Read-only, and it's a record rather than a lever — no incident is acknowledged, no Message Center post is dismissed, no tenant setting is changed here. Sign-in log access is an Entra ID P1 feature on the client's side. And there is no directory change log in this set: a session can tell you who signed in, not who edited a policy last Tuesday.
- The tenant's own record — display name, verified domains, whether it syncs from on-prem AD, its type, and the plans assigned to it.
- The verified domains hanging off the tenant, with the default and initial ones flagged and their capabilities listed.
- The sign-in record for a whole tenant or narrowed to one person — app, IP, location and result on every event, readable only where the client holds Entra ID P1.
- Thirty days of active-user counts per service — the evidence for whether people use what they're licensed for.
- Microsoft's current status for every service this tenant subscribes to — the 'is it them or is it us' check.
- Open and recent incidents and advisories for the tenant, most recently updated first.
- The Message Center posts a tenant has been sent — the roadmap and change notices that explain next month's surprise.
- Apps access more1skills
- App registrations whose client secrets or certificates expire within N days (or have already expired) — the classic "integration will silently break" audit.
- Compliance3skills
- Microsoft Purview retention labels (records-management). BETA Graph surface. Requires RecordsManagement.Read.All (not yet granted to this pack — synthetic, validate at deploy).
- List dlp policies.
- Microsoft Purview eDiscovery cases (legal-hold / investigation inventory). Requires eDiscovery.Read.All (not yet granted to this pack — synthetic, validate at deploy).
- Defender4skills
- List security alerts.
- Get security alert.
- Microsoft Defender security incidents — correlated alert clusters, the top-line "what happened" feed. Requires SecurityIncident.Read.All (not yet granted to this pack — synthetic, validate at deploy).
- Get security incident.
- License optimization3skills
- Per-SKU seat utilization (enabled vs consumed vs idle), sorted most-wasted-first — the headline "are we over-licensed" report.
- Disabled (accountEnabled=false) users who still hold assigned licenses — the classic "forgot to unlicense on offboarding" waste report.
- Licensed, enabled users with no sign-in in the last N days — seat-reclaim candidates. Needs AuditLog.Read.All on core-read to populate signInActivity (not yet granted — synthetic, validate at deploy); until granted, lastSignIn comes back null for every user and inactivity cannot be confirmed.
- Privileged identity2skills
- List pim eligible role assignments.
- List pim active role assignments.
- Posture more3skills
- List directory audit logs.
- Identity provisioning events (cross-app/HR-driven account lifecycle syncs) — visibility into automated provisioning failures. Requires Entra ID P1.
- List secure score control profiles.
- Usage reports4skills
- Per-user, per-service active/inactive detail across the M365 suite (Exchange, OneDrive, SharePoint, Teams, Yammer) for the given period.
- Per-user Teams activity detail (chat/call/meeting counts) for the given period — Teams adoption/idle-seat visibility.
- Per-site SharePoint storage and activity detail for the given period.
- Per-account OneDrive storage and activity detail for the given period.
How it has been taught to work it
Playbooks are the vetted techniques a session loads for this platform — what to check, in what order, and what a number means before it is reported.
- Microsoft 365 domain model (identity & productivity, per client tenant)Always when Microsoft 365 is attached. Its domain model — tenants/users/licences/groups/Intune/security — the per-client binding, the licensing gates, and the read-vs-write boundary.Vetted Sep 2, 2026Always on
- Microsoft 365 licence waste, idle seats, per-service usage detail, expiring app credentialsAre we over-licensed, unused/idle seats, disabled users still holding licences, inactive licensed users, per-user Teams/SharePoint/OneDrive activity, app registrations with expiring secrets or certificates.Vetted Sep 2, 2026
- Microsoft 365 security posture — Secure Score, MFA, admins, Conditional Access, consentHow secure is a client's Microsoft 365, MFA coverage, admin count, Conditional Access, Secure Score, risky sign-ins, app/consent risk, security review, Defender alerts/incidents, PIM/latent privileged access, directory change audit.Vetted Sep 2, 2026
- Microsoft Purview compliance reads — retention labels, DLP policies, eDiscovery cases (not yet live)A client asks about retention/records-management, data-loss-prevention (DLP) policies, or eDiscovery/legal-hold case inventory in Microsoft 365. Read this before attempting any of these three tools — none of them work today.Vetted Sep 2, 2026
- Pax8 ↔ Microsoft 365 — seats bought vs seats owned vs seats assignedAre we paying Pax8 for more Microsoft seats than are assigned — license reconciliation, seat drift, unused/shelfware licenses, billing vs deployment, for one client or across clients.Vetted Aug 31, 2026
- Querying Microsoft 365 — client resolution, result envelopes, and the licence gatesAlways when Microsoft 365 is attached. The read surface, resolving the client tenant, how results come back, paging, and which reads need which licence or app permission.Vetted Sep 2, 2026Always on