Skip to content

O365 Collector Prerequisites

Before using the Tornado O365 Collector, you need to configure the appropriate access permissions in your Microsoft 365 tenant. There are two access methods available, each with different requirements and capabilities.

This is the best method for full automation. It allows Tornado to collect organization-wide data, including user directories, sign-ins, and audit logs—without requiring individual user login.

  1. You must be a Global Administrator in your Microsoft 365 tenant.

Allows Tornado to access only the signed-in user’s data.

  1. A valid Microsoft 365 work account.
  2. Your organization must allow users to consent to applications.

If user consent is disabled in your organization, a Privileged Role Administrator can enable it:

  1. Sign in to the Microsoft Entra Admin Center.
  2. Navigate to: IdentityApplicationsEnterprise applicationsConsent and permissionsUser consent settings
  3. Under User consent for applications, select one of the following:
    • “Allow user consent for apps from verified publishers…” (recommended)
    • “Allow user consent for selected permissions” (for more granular control)
  4. Click Save.

O365 Collector Prerequisites: User consent settings

This feature allows non-admin users to request access to Tornado when the app requires permissions they cannot approve themselves.

You must be a Global Administrator to configure this workflow.

  1. Go to the Microsoft Entra Admin Center.
  2. Navigate to: IdentityApplicationsEnterprise applicationsConsent and permissionsAdmin consent settings
  3. Configure the following options:
SettingRecommended Value
Users can request admin consent to apps they are unable to consent toYes
Who can review admin consent requestsSelect admins, users, groups, or roles
Email notificationsOn
Request expiration remindersOn
Consent request expires after (days)e.g., 3 days
  1. Click Save.

O365 Collector Prerequisites: Admin consent settings

Once Admin Consent Workflow is enabled, non-admin users can request access to Tornado:

The user initiates sign-in to Tornado using their Microsoft 365 credentials.

O365 Collector Prerequisites: Sign in to Tornado

If the user cannot consent to the required permissions, they are prompted to request access from an administrator.

O365 Collector Prerequisites: Request access prompt

The user submits their consent request, which is sent to the designated reviewers for approval.

O365 Collector Prerequisites: Consent request submission

Designated reviewers receive an email notification and can approve or reject the consent request from the Microsoft Entra Admin Center.

O365 Collector Prerequisites: Review consent request

You can monitor or revoke Tornado’s permissions at any time via:

Microsoft Entra Admin CenterEnterprise applicationsBinalyze Tornado