# Microsoft 365

> Single sign-on through Entra ID, licence counts reconciled per client, and incidents raised from mail without leaving the tenant you already manage.

**URL:** https://cubemsp.co.uk/integrations/microsoft-365

The identity platform you already administer, doing the sign-in and the licence count.

Almost every managed service provider is already deep in Microsoft 365 - their own tenant and their clients’. Making CubeMSP use it rather than sit beside it removes two recurring irritations: a separate set of credentials for the service desk, and licence counts held in a spreadsheet that is wrong within six months. Sign-in goes through Entra ID with your existing conditional access, and client licence quantities are reconciled against the services you are billing for.

## Details

- **Category:** Identity & productivity
- **Licence cost:** included, no per-connector charge
- **Platform:** CubeMSP (https://cubemsp.co.uk/platform)

## What syncs

- **Sign-in and user identity** (Into CubeMSP): Authentication through Entra ID, so your conditional access, MFA policy and joiner-leaver process govern access to CubeMSP as well.
- **Client licence counts** (Into CubeMSP): Assigned licence quantities per client tenant, compared against the service quantities you are billing, with the difference listed in both directions.
- **Incidents from mail** (Into CubeMSP): Messages to your support address create or update an incident, threaded onto the existing record rather than starting a new one for every reply.
- **Notifications and review delivery** (Out of CubeMSP): Assignment alerts, breach warnings and published client reviews sent through your own tenant, so they arrive from your domain rather than ours.

## How it behaves

- **Single sign-on you already govern:** No second password to manage or revoke. When somebody leaves and their Entra account is disabled, their CubeMSP access goes with it.
- **Licence drift found in both directions:** The client billed for thirty-eight mailboxes who has thirty-one - and the one with forty-four who is billed for forty. Both are worth finding, and only one of them ever gets reported by the client.
- **The support mailbox keeps working:** Clients carry on emailing the address they know. The queue lives in the system, and nobody has to be retrained on where to send things.
- **Mail from your domain:** Outbound notifications and client reviews sent through your tenant, with your sending reputation and your branding.

## Setup

1. Consent to the CubeMSP application in your own Entra tenant and choose which groups map to which roles.
2. Connect the client tenants you want licence reconciliation for, using the delegated access you already hold.
3. Point your support address at the platform, or forward to it while you run both in parallel for a fortnight.

## Frequently asked questions

**What permissions does it ask for?**

Sign-in and profile for authentication, mail read and send for the queue and notifications, and licence read for reconciliation. Each is consented separately, and licence reconciliation can be declined without affecting anything else.

**Does it need access to our clients’ tenants?**

Only for licence reconciliation, and only for the clients you choose to connect. Everything else works from your own tenant alone.

**Can we enforce MFA and conditional access?**

Yes - because authentication is through Entra ID, your existing policies apply without CubeMSP needing its own equivalent. That is most of the point.

**What happens if the connection breaks?**

Sign-in falls back to local credentials for administrators so you are never locked out, and reconciliation stops rather than showing stale figures as though they were current.

## Related integrations

- **Microsoft Teams** - Assignment, escalation and breach notifications in the channel your engineers already have open, without another application to watch. https://cubemsp.co.uk/integrations/microsoft-teams
- **RMM Platforms** - Alerts from your RMM raise incidents against the right client, site and device - and close again when the alert clears. https://cubemsp.co.uk/integrations/rmm-platforms
- **REST API & Webhooks** - A documented REST API and webhooks on every meaningful event - included in the platform, not licensed per connection. https://cubemsp.co.uk/integrations/rest-api

## Contact

- **Product:** CubeMSP
- **Trading name of:** Cube Systems Limited (company number 17220899, ICO registration number ZC216972)
- **Email:** hello@cubemsp.co.uk
- **Sales:** sales@cubemsp.co.uk
- **Support:** support@cubemsp.co.uk
- **Telephone:** 01234 672 617 (+441234672617)
- **Address:** Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP
- **Opening hours:** Monday to Friday, 9am to 5.30pm
- **Part of:** Crushed Ice Group (https://crushedicegroup.co.uk)
