Appearance
Connecting a Tenant
Onboarding a customer is a one-click flow. A Global Admin of the customer tenant consents once, and Watchmont does the rest: it registers the app, grants every permission and assigns the required roles.
Before you start
- You need to be a SuperAdmin in Watchmont (provisioning is SuperAdmin-only).
- The person consenting must be a Global Administrator of the customer's Microsoft 365 tenant.
- Decide the permission tier: Read-Only (monitoring and reporting) or Read/Write (full management).
Steps
- Go to Companies (the tenant list).
- Click Connect Tenant.
- Choose the permission tier.
- The customer's Global Admin is sent to a Microsoft login and consent screen.
- They sign in and approve the requested permissions.
- Watchmont provisions the tenant automatically and returns to the portal.
What happens automatically
Behind the consent, the platform:
- Creates a dedicated app registration and service principal in the customer tenant.
- Grants the Microsoft Graph and Exchange permissions for the chosen tier. See App Permissions for the full list.
- Assigns the required directory roles (Exchange, Security).
- Generates a client secret and stores it securely (never in the browser).
- Attempts to grant the service principal the Azure Reader role on every subscription, for the Azure resource view.
- Reads the tenant's own organisation name to label the client correctly.
The client is named from Microsoft, not your form
The client name comes from the tenant's own organisation name, so it is always accurate rather than whatever was typed into the connect form.
The two permission tiers
| Read-Only | Read/Write | |
|---|---|---|
| Purpose | Monitor & report | Full management |
| Directory roles | Exchange Admin, Security Reader | Exchange Admin, Security Administrator, User Administrator |
| Write actions (offboard, MFA reset, CA edits) | Hidden / blocked | Available |
The tier is a hard gate: even a Watchmont Admin cannot change a read-only tenant. Read-only tenants show a banner and hide modify controls.
The Azure Reader gotcha
A plain Global Admin does not automatically have Azure subscription access, because Entra roles are not Azure RBAC roles. So the auto-grant of the Azure Reader role only succeeds when the consenting admin is also a subscription Owner or User Access Administrator. If it fails, provisioning still succeeds; the Azure page shows manual steps. This is non-fatal.
Network-only clients
Not every client has a Microsoft 365 tenant. For network or hardware customers, add a network-only company instead. This is a client record with no M365 provisioning, used for reporting and integration mapping (Meraki, UniFi, RoboShadow, Heimdal). These are excluded from all Microsoft sync work but participate fully in the integrations they're mapped to.
Re-authorizing later
As the platform adds features, it sometimes needs new permissions. Tenants connected earlier will show an amber RE-AUTH NEEDED badge in the Companies list, with the missing permissions in the tooltip. Click Re-authorize on that row and have the customer's Global Admin consent again. The badge clears on the next sync. One consent picks up all pending new scopes at once.
After connecting
- The tenant appears in the Companies list and the tenant picker.
- The next background sync pulls in alerts, Secure Score, users and licences.
- Verify data is flowing on the Dashboard after a few minutes.