O365 Collector Prerequisites

Before using the Tornado O365 Collector, you need to configure the appropriate access permissions in your Microsoft 365 tenant. There are two access methods available, each with different requirements and capabilities.

This is the best method for full automation. It allows Tornado to collect organization-wide data, including user directories, sign-ins, and audit logs—without requiring individual user login.

Requirements

  1. You must be a Global Administrator in your Microsoft 365 tenant.

circle-info

Due to the use of Microsoft Graph, this access level is restricted by Microsoft and cannot use lesser privileges.

Allows Tornado to access only the signed-in user's data.

Requirements

  1. A valid Microsoft 365 work account.

  2. Your organization must allow users to consent to applications.

circle-exclamation

If user consent is disabled in your organization, a Privileged Role Administrator can enable it:

  1. Navigate to: IdentityApplicationsEnterprise applicationsConsent and permissionsUser consent settings

  2. Under User consent for applications, select one of the following:

    • "Allow user consent for apps from verified publishers..." (recommended)

    • "Allow user consent for selected permissions" (for more granular control)

  3. Click Save.

O365 Collector Prerequisites: User consent settings

This feature allows non-admin users to request access to Tornado when the app requires permissions they cannot approve themselves.

Requirements

You must be a Global Administrator to configure this workflow.

  1. Navigate to: IdentityApplicationsEnterprise applicationsConsent and permissionsAdmin consent settings

  2. Configure the following options:

Setting
Recommended Value

Users can request admin consent to apps they are unable to consent to

Yes

Who can review admin consent requests

Select admins, users, groups, or roles

Email notifications

On

Request expiration reminders

On

Consent request expires after (days)

e.g., 3 days

  1. Click Save.

O365 Collector Prerequisites: Admin consent settings
circle-check

Once Admin Consent Workflow is enabled, non-admin users can request access to Tornado:

1. Sign in to Tornado

The user initiates sign-in to Tornado using their Microsoft 365 credentials.

O365 Collector Prerequisites: Sign in to Tornado

2. Request Access

If the user cannot consent to the required permissions, they are prompted to request access from an administrator.

O365 Collector Prerequisites: Request access prompt

The user submits their consent request, which is sent to the designated reviewers for approval.

O365 Collector Prerequisites: Consent request submission

4. Review and Approve Request

Designated reviewers receive an email notification and can approve or reject the consent request from the Microsoft Entra Admin Center.

O365 Collector Prerequisites: Review consent request

Security & Management

You can monitor or revoke Tornado's permissions at any time via:

Microsoft Entra Admin CenterEnterprise applicationsBinalyze Tornado

circle-info

All data access is controlled via OAuth2 and Microsoft Graph scopes.

Resources

Last updated

Was this helpful?