Onboarding

Customer onboarding checklist

Follow the recommended order for tenant setup, Microsoft connection, Office 365 authorization, posture setup, validation, reporting, and assistant testing.

Updated May 5, 2026 | 12 min

Who should use this checklist

Customer tenant admin or Microsoft Global Administrator who can grant consent and confirm tenant values.
Partner admin or MSP operator responsible for creating the customer tenant and running setup.
Implementation lead coordinating secrets, authorization windows, reporting, and handoff.
SOC or security owner validating that the first findings and reports are useful.

Recommended onboarding order

  1. Create or select the customer tenant

    Confirm the ITDR tenant record, customer name, primary domain, and implementation owner before connector work starts.

  2. Invite the customer tenant admin

    Give the right person access so they can review setup status, reports, and connector health.

  3. Choose Microsoft connector mode

    Use delegated mode for quick authorization, or app-only mode when the customer wants service-principal-based production ingestion.

  4. Authorize Microsoft Graph

    Grant the required read permissions, then validate organization and sample identity data in ITDR.

  5. Authorize Office 365 Management

    Enable the Office 365 lane when mailbox, audit, or workload activity is part of the detection scope.

  6. Run the first sync

    Start ingestion and review connector status, warning buckets, and last-run timestamps.

  7. Validate telemetry

    Confirm identity inventory, sign-in signals, audit data, alerts, incidents, and Secure Score where available.

  8. Configure posture connector

    Add Azure or Microsoft 365 posture credentials if the customer needs cloud configuration-risk visibility.

  9. Configure notification channels

    Add Slack, Teams, or PagerDuty routing so alerts, incidents, connector degradation, and response-action outcomes reach the customer or partner operations channel.

  10. Generate the first report

    Create a one-time assessment or weekly report and confirm that the findings match the customer environment.

  11. Test the assistant with grounded prompts

    Ask a few operational questions and verify that answers include evidence, caveats, and relevant tenant context.

Customer setup packet

Collect these values before the implementation session. Do not paste secrets into tickets, email threads, or chat channels unless your organization has approved that secret-sharing process.

ItemOwnerValue to collectWhere it is used
Customer tenant name and primary domainPartner or implementation leadLegal/customer display name and primary domainTenant selection, reporting labels, and support handoff
Microsoft tenant IDCustomer adminDirectory tenant ID from Microsoft EntraMicrosoft connector configuration and validation
Customer admin accountCustomer adminAdmin email that can approve consent or coordinate approvalDelegated authorization, invite routing, and follow-up
Connector mode decisionCustomer security ownerDelegated or app-onlyDetermines the Microsoft setup guide and permission flow
App-only client ID and secretCustomer adminApplication ID and secret value, if app-only mode is usedBackground Microsoft Graph ingestion
Office 365 authorization ownerCustomer adminPerson who can approve Office 365 Management accessWorkload audit and activity ingestion
Azure subscription IDsCloud platform ownerSubscription IDs in posture scope, if Azure posture is usedPosture connector scoping and assessment coverage
Report recipientsCustomer security ownerStakeholders who need assessment or weekly report outputReport review, export, and customer communication
Notification destinationPartner or tenant adminSlack incoming webhook URL, Teams workflow webhook URL, or PagerDuty routing keySettings -> Notification channels
Assistant provider decisionPlatform ownerUse default assistant mode or bring a provider API keyControls assistant depth, model choice, and operating cost

Validation gates

  • Identity inventory loads with expected users, groups, and basic tenant metadata.
  • Sign-in, audit, alert, or incident signals appear for the expected time window.
  • Office 365 Management lane is authorized and shows import activity when workload audit data is in scope.
  • Secure Score or security posture data appears where Microsoft permissions and tenant licensing support it.
  • Posture findings appear for the expected provider, subscription, or Microsoft 365 scope.
  • First assessment or weekly report can be generated and exported.
  • Assistant answers include tenant-specific evidence, source references, and clear caveats when data is missing.

Minimum vs full access path

If customer approval is blocked by permission concerns, start smaller and expand after the first value is proven.

Minimum read-only detection

Start with identity, directory, audit, and reporting permissions. This is usually the lowest-friction customer approval path.

Detection plus enrichment

Add risk, alert, incident, Secure Score, and workload data so triage answers have more evidence.

Detection plus response

Add carefully approved action permissions only when the customer wants ITDR to support containment workflows.

Posture plus remediation

Add cloud posture credentials and remediation planning once baseline ingestion is stable.

First questions to ask the assistant

Use questions like these after connector data and posture findings are available. Good answers should cite evidence and explain what data is missing.

  • What should we focus on first across this tenant security posture?
  • Which identities should we investigate first and why?
  • Where are the largest MFA or conditional access gaps?
  • Are our Microsoft and posture connectors healthy?
  • Summarize this tenant risk for an executive review.

Completion handoff

Keep this handoff free of raw secrets. Reference the approved vault, ticket, or customer-owned secret channel when credentials are required.

Customer tenant:
Microsoft tenant ID:
Connector mode:
Graph authorization:
Office 365 authorization:
First sync status:
Posture provider:
First report generated:
Assistant validation prompt:
Open issues: