Let’s take a look at the newest integration within Datto RMM – Microsoft 365.
Step by Step:
- Today we’re going to be taking a look at Datto RMM and a new integration as you may have guessed from the title we’re going to be taking a look specifically at Datto’s newest integration that was marked for release at this year’s DattoCon Microsoft 365 let’s go ahead and hop into here and get started.
- When logged into Datto RMM on the left-hand side we should see an area for Microsoft 365.
- If you don’t see it here, you can go and click setup and then Integrations and click on Microsoft 365 from here.
- When you click onto Microsoft 365 within the portal it’ll bring you to the configuration of the integration.
- From here it gives us a brief synopsis of what the integration does so we can see the Microsoft 365 integration provides you with multi-tenant functionality for your M365 tenant directly from Datto RMM upon connecting your Microsoft CSP tenant Datto RMM will automatically fetch all your client tenants and users for you to manage in one place. Benefits include quick access to user data and common actions such as resetting a user’s password.
- Before we can begin with the integration there are a few prerequisites that are needed.
- First and foremost is that this Microsoft 365 integration must be made with a Microsoft Azure account with Cloud solution provider or CSP.
- Datto recommends setting up a data specific account for this such as data integration at your domain. This recommendation is to ensure the integration bypasses conditional access policies.
- The integrating service must be a global administrator for initial setup, Global administrator rights are not required perpetually however so data recommends leveraging privileged identity management or Pim so the account is only eligible for the role when required.
- The authenticating user must also use Microsoft multifactor authentication MFA which can be enforced through conditional access or per user MFA settings. MFA cannot be performed through a third party such as Duo and while MFA cannot be provided through a third party for this user MFA through a third-party application is adequate for other users in the account.
- Additionally, the user must be excluded from any policies enforcing sign on restrictions outside of MFA and once you have the account set up you want to go ahead and configure these settings for the admin agent through Microsoft partner Center or Microsoft entra we’re going to show you that here.
- Within the Microsoft partner center you’ll see under the user management the setting we want to take a look at here will say assist your customer as admin agent you want to make sure that is set up.
- Once completed work can be started on the gdap relationship configuration so we’ll see that here this will allow the authenticating user to have a granular delegated admin privileges or gdap and you need to make sure that this relationship exists for all the client tenants.
- Each gdap relationship must have a security group assigned and the integrating service account must be part of that Security Group.
- The group can be granted permissions for one of the following roles so we see here Global administrator the other two allowed would be privileged rooll admin or Cloud application admin.
- Once you have all of these prerequisites completed we can now turn on the integration.
- From here you will need your tenant ID once go and click turn on we’ll see here the tenant ID will allow you to be filled in there if you don’t know where your tenant ID is at you can find that on the overview page.
- The tenant ID you want to go ahead and paste that onto your integration and then go ahead and click save.
- Once saved you will see it transition into an integrating state, this will then go ahead and prompt you to sign into a Microsoft account
- You will go sign into the one that you use for the tenant there and once signed in you will see an additional popup here.
- This additional popup is going to be permissions required some of them will be for the Datto API and once this is configured we’ll go ahead and click accept you’ll then go back to your Microsoft 365 integration and you’ll see that it’ll now show saved and authenticated on the integration.
- From here if we go and click on that second tab where it says tenets it’ll then pull in all of the tenants by default for the CSP account that you pulled in for by default when you initially set it up here everything is going to be deactivated so you want to make sure that after the initial setup you go in here and you manually sync all of the objects because these will be deactivated on the first setup.
- To do that you can go ahead and click individually these check marks here or click at the very top if you want all of them you’ll then see It’ll select all of them.
- To sync all we do is just very simply go ahead and click that sync button and upon doing so it’ll have you confirm just to make sure that you want to do it for the ones you selected.
- Go ahead and click confirm and once you complete you’ll then see that the status will no longer show deactivated and it’ll show synced for all of the clients that you have chosen to sync on there and after that the configuration is complete.
- So that’s how you set up and configure the Microsoft 365 integration.