Skip to content
All integrations
Microsoft 365

Review Microsoft 365 identities and file sharing.

Synchronize your directory, then connect OneDrive and SharePoint to review file exposure. Add Teams separately to send employees security notifications.

Directory sync · Separate OneDrive, SharePoint, and Teams connections

Product illustration · Example data and workflow.

Capabilities

What this integration covers.

01

Choose your directory import scope.

Synchronize eligible users and groups, across your directory or a selected Entra security group.

02

Act on exposed files.

Connect OneDrive and SharePoint separately to review sharing and remove eligible item permissions.

03

Reach employees in Teams.

Enable the separate Teams connection to send employees security notifications.

Example workflow

Remove unnecessary access to a shared document.

How the integration supports a specific security task.

  1. 01

    Identify the sharing issue

    A separate OneDrive or SharePoint connection surfaces an eligible sharing issue.

  2. 02

    Review access

    Your team reviews the item and decides which access is still needed.

  3. Remove the permission

    An eligible permission is removed through the connected Data Protection source.

Related capability

Explore this part of the platform.

Explore apps & access

Before you connect

Coverage, permissions, and requirements.

The Microsoft 365 base connection synchronizes directory data. Teams notifications, phishing simulations, and SharePoint or OneDrive Data Protection use separate Microsoft applications or consent flows.

Explore security & privacy
Which Microsoft role should complete setup?

Use a Global Administrator for the complete flow. Some tenant-wide permissions require that role even when an Application Administrator is recognized during part of sign-in.

Does group scope reduce the permissions granted to elba?

No. It limits which directory records elba queries and stores, while the application permissions accepted during tenant consent remain tenant-wide.

Can the selected group be changed later?

Not after administrator consent. Choose and validate the intended import boundary before authorizing the connection.

Are SharePoint, OneDrive and Teams included automatically?

No. These capabilities use separate applications or consent flows and must be reviewed and enabled independently.

Coverage and requirements
  • Group scope is a query-and-storage boundary in elba, not a Microsoft authorization boundary; application permissions remain tenant-wide.
  • The import scope cannot be changed after administrator consent has been granted.
  • Group mode includes eligible direct members only; guests, disabled accounts and nested-group-only members are excluded.
  • A group-scoped sync requires the elba organization owner to remain an eligible direct member of the selected group.
  • The base directory connection does not imply that Teams, phishing, SharePoint or OneDrive capabilities are enabled.

Other applications

Review more integrations.

All integrations

Discuss your requirements

Evaluate Elba for Microsoft 365.

Review the available capabilities, required permissions, and setup for your environment with our team.

Request a demo