Connect Microsoft 365

License Maxing connects to your Microsoft 365 tenant through Microsoft Entra using application permissions granted by admin consent. There is nothing to install.

Granting consent

  1. In Settings → Microsoft 365, choose Connect.
  2. Sign in with an account that can grant admin consent for your tenant.
  3. Review the requested permissions and approve.

You are redirected back to License Maxing and the connection status updates to Connected.

Permissions we request and why

Permission Used for
Directory.Read.All Reading users and license assignments
User.Read.All User profile fields shown in reports (name, department, sign-in state)
Reports.Read.All Usage reports: mail, Teams, OneDrive and mailbox/storage statistics
AuditLog.Read.All Last sign-in activity used for inactivity detection
ReportSettings.ReadWrite.All Detecting (and, with your approval, disabling) report anonymization so usage rows can be matched to users
User.ReadWrite.All Only exercised when you execute offboarding or savings plans — disabling accounts and changing license assignments

Reading and reporting never modifies your tenant. Write operations happen only when someone in your organization explicitly executes an offboarding action or savings plan, and every execution is recorded in the audit log.

About report anonymization

Some tenants have Microsoft 365 usage reports set to conceal user names. When that setting is on, usage rows can't be matched to users, so activity analytics would be empty. License Maxing detects this during sync and — because it can't produce useful results otherwise — remediates the report privacy setting so display names appear in reports. If your compliance posture requires anonymized reports, contact support before connecting.

Verifying data is flowing

After the first sync completes, check:

  • Licenses shows your SKU inventory with assigned counts.
  • Reports → Email activity shows per-user send/receive counts and mailbox storage.
  • The freshness badge on report pages shows when Microsoft last refreshed usage data (Microsoft's own reports lag by roughly 24–48 hours).

If a sync fails, organization admins receive an email alert (if notifications are enabled) and the run appears in Settings → Sync history with the error.