Customers & onboarding
Onboarding a customer with the setup wizard
Pick the modules to assess, generate an onboarding link and send it to the customer's Global Administrator. They approve each module and the wizard assigns the read-only roles.
- Who can do this
- Admin or Owner creates the link
- Plan
- All plans
- Time
- About 5 minutes for the customer
Before you start
- The customer is added (Adding a customer).
- You know who the customer's Global Administrator is (or you are that administrator).
- For an opt-in module (Power Platform or SharePoint Advanced): the customer has agreed to grant access that is not read-only.
Choose modules and generate the link
Open Customers and select the customer. On the Connect this customer card, select Choose modules.
In Choose modules for customer: Core is Required and always included. The available read-only modules are pre-selected; clear the ones you don't need. Expand the permissions line under a module (for example 6 permissions + Global Reader role) to see every permission and why it's needed.
To include an opt-in module marked Not read-only · opt-in, select it and then tick I understand and the customer has agreed to grant this write-capable access. (Recorded in the audit log with my name.)
Select Generate onboarding link. The dialog changes to Send the onboarding link.
Select Copy link and send it to the customer's Global Administrator, or select Open if you are that administrator. Then select Done.
About the onboarding link
- The link opens
app.m365assessments.com/onboard. The customer's administrator doesn't need an M365Assessments account. - It is valid for 72 hours (the exact expiry is shown under the link) and works only for this customer’s tenant.
- Who approves: a Global Administrator of the customer tenant (or a Privileged Role Administrator together with Cloud Application Administrator). The Power Platform module's registration needs a Power Platform Administrator or Global Administrator.
- Send the administrator this guide for customer administrators with the link.
Security note
The link grants nothing by itself. Consent is still given at Microsoft by that tenant’s own administrator, and consent from any other tenant is refused. The link travels after the “#” in the URL, so it never reaches server logs.
Track progress on the Modules card
The customer page updates automatically while you wait. On the Modules card, each module shows:
- Consent pending → Consented once the administrator approves it at Microsoft.
- For Exchange & Security and Microsoft Teams: Global Reader needed → Global Reader · verifying on next run after the wizard's final step → Global Reader verified after the first assessment.
- For Power Platform: Power Platform registration needed → Power Platform registration · verifying on next run → Power Platform registration verified.
As soon as Core is consented, the customer turns Active and you can run an assessment. Modules that are still pending are simply left out of the run until they are approved.
Tip
Link expired, or the administrator only finished some modules? Select Resend link on the Modules card to generate a fresh link for every module that still needs action, or Onboarding link on a single module's row.
What happens next
Run the first assessment (Running an assessment). It also verifies the Global Reader and Power Platform steps with the module apps' own access.
Troubleshooting
The administrator sees “This onboarding link has expired”
Links expire after 72 hours. Select Resend link on the Modules card and send the new link.
A module shows “Consent failed”
Select Onboarding link on that module's row and ask the administrator to approve it again. Common causes: Admin consent errors.
A module shows “Global Reader missing”
The role wasn't found on the last run. The administrator can re-run the wizard's final step or assign it manually: Assigning Global Reader manually. Role changes can take up to an hour to reach Exchange Online and Purview.
The customer's network can't open the link
Last updated