SalesCollab

Microsoft 365 integration

Sync Microsoft 365 users, Intune devices and licences into one register.

One app registration in Entra ID and AssetTrack keeps your people, laptops and licence assignments in sync every six hours. See who has which Microsoft 365 E3, which laptops are compliant, and where money is leaking on unused Copilot seats and lingering E5s.

What syncs automatically

  • Entra ID users → AssetTrack employees (matched by email address, then user principal name)
  • Intune-managed devices → asset register (matched by hardware serial number)
  • Microsoft 365 & Entra licence SKUs → licence catalogue with human-readable names
  • Per-user licence assignments → who has which seat, refreshed every 6 hours
  • Device compliance state, last check-in, primary user, OS version and enrolment date
  • Group memberships from Entra ID → available as filters and audience segments in AssetTrack
  • Autopilot deployment profile assignments (where present) → tied back to the asset record

Ten-minute setup — no agent on your endpoints

Create an app registration in Entra ID, grant three read-only Microsoft Graph permissions (User.Read.All, Device.Read.All, Organization.Read.All), and paste the Tenant ID, Application (Client) ID and a Client Secret into AssetTrack. The first sync starts within a minute; subsequent syncs run every six hours and can be triggered on demand from the integration page.

The integration is entirely read-only — AssetTrack never modifies your tenant, disables accounts, wipes devices, or writes back to Graph. If you disconnect, your data stays and the sync simply stops. Client secrets are stored encrypted at rest and never returned to the browser.

Serial-first matching keeps your register clean

Intune reports the hardware serial for every device. AssetTrack matches on serial first, so a laptop already in your register (from a purchase order, network discovery, or CSV import) is updated in place — not duplicated. Devices Intune sees but AssetTrack doesn't land in the discovery queue for one-click enrolment, with the pre-populated make, model, serial, primary user and warranty end where Intune knows it.

The same match pipeline covers Entra ID users: existing employees are updated by email, new hires appear as discoveries. Leavers detected by an Entra sign-in-blocked state are surfaced in the offboarding view so IT can reclaim their kit and revoke their licences before the next payroll run.

See where Microsoft money is being spent

Every licence SKU is decoded into a friendly name: Microsoft 365 E3, Business Premium, Copilot for Microsoft 365, Power BI Pro, Entra ID P2, Intune Plan 1, Exchange Online Plan 2, and dozens more. The licence view shows total seats, assigned seats, unassigned seats you're paying for, cost per seat, and every employee holding a seat.

Combined with last-sign-in data from Entra, you can spot the R390/month E5 assigned to someone who left three months ago, the Copilot seat nobody activated, and the Power BI Pro count that quietly grew from 12 to 47. Export any of it to CSV for finance, or trigger an internal review workflow from within AssetTrack.

Compliance and device-posture reporting

Intune's compliance state (compliant, non-compliant, in grace period, error) flows into AssetTrack alongside the asset's own status. That means you can answer 'which finance-team laptops are non-compliant AND out of warranty AND due for refresh in Q3?' in a single filter — the sort of cross-cutting report that usually needs a spreadsheet and a Friday afternoon.

For MSPs, the same view scoped per customer tenant becomes a monthly compliance report you can send from AssetTrack without opening the Intune console.

Multi-tenant and MSP-friendly

Each AssetTrack organisation connects to its own Microsoft 365 tenant. MSPs manage one customer per tenant, with one AssetTrack login switching between them — no shared admin accounts, no browser profile juggling, no CSP delegated permissions to negotiate.

Where a customer already runs Lighthouse or Partner Center, AssetTrack sits alongside as the asset and licence system of record, complementing the operational tooling rather than replacing it.

What we DON'T do (on purpose)

  • We don't request Mail, Files, Calendars, Sites, or Chat permissions — ever
  • We don't write back to Entra or Intune, so we can't disable accounts, remove licences, or wipe devices
  • We don't need Global Admin day-to-day — admin consent is a one-off during setup
  • We don't copy your directory into a third-party CRM or resell any of the data
  • We don't need on-prem AD Connect or ADFS — Entra alone is enough

Frequently asked questions

What Microsoft Graph API permissions do you need?

Three application-level, read-only permissions: User.Read.All, Device.Read.All and Organization.Read.All. We never request Mail, Files, Calendars, Sites, or Chat. Global admin consent is required once, at setup, to grant these app-level permissions.

How often does the sync run?

Every six hours automatically. You can also trigger a manual sync from the integration page at any time — useful right after onboarding a batch of new starters or reclaiming licences from leavers.

How do you store the client secret?

The client secret is stored encrypted at rest in an isolated table with restrictive RLS, and used only to fetch a Microsoft Graph access token during sync. Rotate it in Entra ID whenever you like — paste the new value into AssetTrack and the next sync uses it immediately.

What if my tenant doesn't have Intune?

User and licence sync work with any Microsoft 365 or Entra ID tenant. Device sync additionally requires Intune (Microsoft 365 Business Premium, Microsoft 365 E3/E5, or any plan bundling Intune). Without Intune, devices can still be populated via the network discovery agent, CSV import, or manual entry.

Will this create duplicate devices in my register?

No. Matching runs serial-first, then falls back to Azure AD device ID, then hostname. Anything the pipeline can't confidently match lands in the discovery queue for one-click confirmation — so duplicates need an explicit human action, not a silent import.

Can I disconnect later?

Yes. Disconnecting stops the sync immediately and leaves your existing asset, user and licence records untouched. Revoke the app registration in Entra ID at the same time if you want zero lingering access.

Does this work with Government (GCC / GCC High) tenants?

The standard integration targets the commercial (graph.microsoft.com) endpoint. GCC and GCC High tenants use different Graph endpoints and consent flows — get in touch and we'll enable the alternate endpoint for your organisation.

How is the licence catalogue kept up to date as Microsoft renames SKUs?

AssetTrack ships a SKU-to-friendly-name catalogue covering the common Microsoft 365, Office 365, Entra, Intune, Power Platform, Defender, Teams Phone and Copilot SKUs, and falls back to the raw SKU part number for anything unrecognised. The catalogue is updated as Microsoft publishes new SKUs.

Can two AssetTrack organisations sync from the same tenant?

Technically yes — each connection is scoped to an AssetTrack organisation — but it's rarely what you want. For MSPs, run one AssetTrack organisation per customer tenant; for enterprises with multiple business units on one tenant, use audiences and group filters inside a single AssetTrack organisation instead.

Does the integration cost extra?

No. The Microsoft 365 integration is included on every paid plan (and available during the free trial). You pay Microsoft for your Graph API usage, but Graph reads of this shape are free within Microsoft's fair-use limits.

What happens when a user leaves the company?

When Entra blocks the user's sign-in (or the account is deleted), AssetTrack marks the employee as offboarded and surfaces every asset assigned to them and every licence they hold, ready for reclamation before the next billing cycle.

Know what you own. Who has it. What it’s worth.

Free workspace while we finish billing. Import a CSV and you’ll know within an hour whether AssetTrack fits.