Connect Microsoft 365
Vigil assesses Microsoft 365 against CISA's SCuBA Secure Configuration Baselines using ScubaGear. It connects via Microsoft's admin-consent flow with read-only application permissions — a Global Administrator grants consent once, and Vigil never writes to your tenant.
What you need
- A Global Administrator on the tenant to grant admin consent (one-time).
- Nothing to install — the connection is agentless and read-only.
Steps
- In Vigil, go to Settings → Integrations and click Connect Microsoft 365.
- Sign in as a Global Administrator when Microsoft prompts you.
- Review the requested read-only permissions and accept the consent.
- You'll be returned to Vigil with the tenant marked Connected.
- Click Run check to queue a scan.
Why a Microsoft 365 scan can take longer
Some ScubaGear connectors require Windows, so Microsoft 365 scans run on a scheduled Windows scanner rather than Vigil's always-on Linux worker. The scan is queued and the Integrations row updates automatically as it progresses — you don't need to keep the page open.
What it covers
A Microsoft 365 scan contributes verified evidence to your Identity & Access domain today. As additional connectors are enabled, the same connection will extend to Email Security, Data Protection, and Monitoring & Logging.