The identity platform you already administer, doing the sign-in and the licence count.

CubeMSP and Microsoft 365

Single sign-on through Entra ID, licence counts reconciled per client, and incidents raised from mail without leaving the tenant you already manage.

Almost every managed service provider is already deep in Microsoft 365 - their own tenant and their clients’. Making CubeMSP use it rather than sit beside it removes two recurring irritations: a separate set of credentials for the service desk, and licence counts held in a spreadsheet that is wrong within six months. Sign-in goes through Entra ID with your existing conditional access, and client licence quantities are reconciled against the services you are billing for.

What moves

Exactly what is synced, and which way

Being specific about this up front avoids the single most common integration disappointment - discovering after go-live that one field never travelled.

  • Into CubeMSP

    Sign-in and user identity

    Authentication through Entra ID, so your conditional access, MFA policy and joiner-leaver process govern access to CubeMSP as well.

  • Into CubeMSP

    Client licence counts

    Assigned licence quantities per client tenant, compared against the service quantities you are billing, with the difference listed in both directions.

  • Into CubeMSP

    Incidents from mail

    Messages to your support address create or update an incident, threaded onto the existing record rather than starting a new one for every reply.

  • Out of CubeMSP

    Notifications and review delivery

    Assignment alerts, breach warnings and published client reviews sent through your own tenant, so they arrive from your domain rather than ours.

How it behaves

The detail that decides whether it is actually useful

  • Single sign-on you already govern

    No second password to manage or revoke. When somebody leaves and their Entra account is disabled, their CubeMSP access goes with it.

  • Licence drift found in both directions

    The client billed for thirty-eight mailboxes who has thirty-one - and the one with forty-four who is billed for forty. Both are worth finding, and only one of them ever gets reported by the client.

  • The support mailbox keeps working

    Clients carry on emailing the address they know. The queue lives in the system, and nobody has to be retrained on where to send things.

  • Mail from your domain

    Outbound notifications and client reviews sent through your tenant, with your sending reputation and your branding.

Setting it up

Three steps, done during implementation

  1. Consent to the CubeMSP application in your own Entra tenant and choose which groups map to which roles.

  2. Connect the client tenants you want licence reconciliation for, using the delegated access you already hold.

  3. Point your support address at the platform, or forward to it while you run both in parallel for a fortnight.

Questions

What people ask about this one

  • Sign-in and profile for authentication, mail read and send for the queue and notifications, and licence read for reconciliation. Each is consented separately, and licence reconciliation can be declined without affecting anything else.

  • Only for licence reconciliation, and only for the clients you choose to connect. Everything else works from your own tenant alone.

  • Yes - because authentication is through Entra ID, your existing policies apply without CubeMSP needing its own equivalent. That is most of the point.

  • Sign-in falls back to local credentials for administrators so you are never locked out, and reconciliation stops rather than showing stale figures as though they were current.

Microsoft 365

Check the Microsoft 365 detail before you commit

Send us the specifics - your chart of accounts, your tax treatment, your product structure - and we will tell you exactly how it maps rather than promising it will be fine.