Customers & onboarding
For customer administrators: approving an onboarding link
Your service provider sent you an M365Assessments onboarding link. Here is what each step does, what you approve and how to remove access later.
- Who can do this
- Global Administrator of the tenant being assessed
- Plan
- No M365Assessments account needed
- Time
- 2–5 minutes
Before you start
- The onboarding link from your service provider (or your own IT team). Use the same browser for every step.
- A Global Administrator account of the tenant being connected (or Privileged Role Administrator plus Cloud Application Administrator).
Steps
Open the link. The page Connect your tenant explains who asked for the assessment, which modules they selected, how many steps are left and until when the link is valid.
Under Approve access, the next module is highlighted. Read its summary and permission list, then select Grant consent.
Sign in to Microsoft with an administrator account of this tenant. Microsoft lists every permission the module requests. Select Accept.
You're returned to the wizard with Consent granted and the next module highlighted. Repeat for each module.
Final step (only if a module needs it): select Sign in to assign roles, sign in once more, then select Assign roles now. The page assigns Microsoft's built-in, read-only Global Reader role to the Exchange & Security and Teams module apps, and registers the Power Platform module app if it was selected.
When you see All set — thank you, you can close the window.
What you are approving
- Each module is a separate Microsoft Entra application named “M365 Assessment – …”, with exactly the permissions listed on the consent screen.
- Read-only modules can view configuration but cannot change settings, users or data.
- Modules marked Not read-only · opt-in were explicitly selected by your provider. Microsoft offers no narrower permission for them; M365Assessments only reads with them.
- Global Reader is a view-only directory role. It lets Exchange Online, Purview and Teams PowerShell read settings and cannot change anything.
Security note
The role assignment happens in your browser with your own sign-in. Your token is never sent to M365Assessments, and the “M365 Assessment – Onboarding” app has only delegated permissions, so it keeps no access after you close the page.
If the in-browser step fails
Some tenant policies block the in-browser role assignment. The row then shows Failed with the reason. Select Do it with PowerShell instead, then Copy script, run it as a Global Administrator, and select I've done this. The next assessment confirms the role. You can also use the Microsoft Entra admin center: Assigning Global Reader manually.
Removing access later
You can remove access at any time without contacting anyone: Microsoft Entra admin center › Enterprise applications › search for “M365 Assessment” › open each app › Properties › Delete. Step by step: Removing M365Assessments from a tenant.
Troubleshooting
“Signed in to a different tenant”
The account you used belongs to another tenant. Select Use another account and sign in with an administrator of the tenant named on the page.
“This onboarding link has expired”
Ask your service provider for a new onboarding link. Links are valid for 72 hours.
I declined a consent by mistake
Open the onboarding link again in the same browser and select Grant consent for that module. If you land on a page saying consent wasn’t completed, just re-open the link: the wizard resumes where you left off.
“Consent was granted from a different Microsoft 365 tenant”
Sign in to Microsoft with an administrator account from the tenant being connected, not a guest account from another tenant.
Changes take a while to show
Role assignments can take up to an hour to reach Exchange Online and Purview. The first assessment verifies everything automatically.
Last updated