Connect Microsoft 365
Read provisioned Microsoft 365 license seats, across your whole partner book or one client at a time. Read-only, with least-privilege access.
Microsoft 365 is a vendor connector: it tells BillRecon how many of each license a client actually has. There's one Microsoft 365 connector, and it can reach your clients two ways. Both are read-only. Connecting never changes anything in a client's tenant.
Two ways to connect
In Connections, choose Microsoft 365, then pick how you reach your clients:
- All your clients at once. Sign in once as your partner admin and approve read access. BillRecon finds the clients you have a partner (GDAP) relationship with and shows you a review screen of who it can reconcile. Nothing syncs until you confirm.
- One client at a time. A single client's Microsoft admin approves read access to their own tenant, and BillRecon reads just that one.
A client you reach both ways shows up as a single entry, not two. BillRecon connects by what it can read, not by how the connection was made.
Least-privilege access
BillRecon asks for read-only access, and only to what it uses: your partner relationships, your clients' subscriptions, and their users. It never requests write access for reconciliation.
For the role you grant in each client tenant:
- Directory Readers is enough to read licenses and users. That's the least-privilege role for reconciliation, and what we recommend.
- The optional device and sign-in reads (below) need Global Reader instead, and sign-in activity also needs the client's Entra ID P1. Grant these only on the clients where you want those extras.
What it reads
After you confirm, BillRecon reads how many of each license every client has provisioned. License names show in plain English, not vendor codes.
Reading device inventory and sign-in activity is optional and off by default. Each is a separate switch on the connection, and turning one on asks for its own additional approval, so a plain connection reads license counts and nothing more until you opt in.
Reconnecting
If a connection expires, reconnect it in place from the connection's page. The same connection is repaired (you don't end up with a duplicate), and signing in as a different partner than the one on record is rejected.
Next: connect your PSA, then walk the reconciliation workflow. Back to all connectors.