Onboarding
Customer onboarding checklist
Follow the recommended order for tenant setup, Microsoft connection, Office 365 authorization, posture setup, validation, reporting, and assistant testing.
Updated May 5, 2026 | 12 min
Who should use this checklist
Recommended onboarding order
Create or select the customer tenant
Confirm the ITDR tenant record, customer name, primary domain, and implementation owner before connector work starts.
Invite the customer tenant admin
Give the right person access so they can review setup status, reports, and connector health.
Choose Microsoft connector mode
Use delegated mode for quick authorization, or app-only mode when the customer wants service-principal-based production ingestion.
Authorize Microsoft Graph
Grant the required read permissions, then validate organization and sample identity data in ITDR.
Authorize Office 365 Management
Enable the Office 365 lane when mailbox, audit, or workload activity is part of the detection scope.
Run the first sync
Start ingestion and review connector status, warning buckets, and last-run timestamps.
Validate telemetry
Confirm identity inventory, sign-in signals, audit data, alerts, incidents, and Secure Score where available.
Configure posture connector
Add Azure or Microsoft 365 posture credentials if the customer needs cloud configuration-risk visibility.
Configure notification channels
Add Slack, Teams, or PagerDuty routing so alerts, incidents, connector degradation, and response-action outcomes reach the customer or partner operations channel.
Generate the first report
Create a one-time assessment or weekly report and confirm that the findings match the customer environment.
Test the assistant with grounded prompts
Ask a few operational questions and verify that answers include evidence, caveats, and relevant tenant context.
Customer setup packet
Collect these values before the implementation session. Do not paste secrets into tickets, email threads, or chat channels unless your organization has approved that secret-sharing process.
| Item | Owner | Value to collect | Where it is used |
|---|---|---|---|
| Customer tenant name and primary domain | Partner or implementation lead | Legal/customer display name and primary domain | Tenant selection, reporting labels, and support handoff |
| Microsoft tenant ID | Customer admin | Directory tenant ID from Microsoft Entra | Microsoft connector configuration and validation |
| Customer admin account | Customer admin | Admin email that can approve consent or coordinate approval | Delegated authorization, invite routing, and follow-up |
| Connector mode decision | Customer security owner | Delegated or app-only | Determines the Microsoft setup guide and permission flow |
| App-only client ID and secret | Customer admin | Application ID and secret value, if app-only mode is used | Background Microsoft Graph ingestion |
| Office 365 authorization owner | Customer admin | Person who can approve Office 365 Management access | Workload audit and activity ingestion |
| Azure subscription IDs | Cloud platform owner | Subscription IDs in posture scope, if Azure posture is used | Posture connector scoping and assessment coverage |
| Report recipients | Customer security owner | Stakeholders who need assessment or weekly report output | Report review, export, and customer communication |
| Notification destination | Partner or tenant admin | Slack incoming webhook URL, Teams workflow webhook URL, or PagerDuty routing key | Settings -> Notification channels |
| Assistant provider decision | Platform owner | Use default assistant mode or bring a provider API key | Controls assistant depth, model choice, and operating cost |
Validation gates
- Identity inventory loads with expected users, groups, and basic tenant metadata.
- Sign-in, audit, alert, or incident signals appear for the expected time window.
- Office 365 Management lane is authorized and shows import activity when workload audit data is in scope.
- Secure Score or security posture data appears where Microsoft permissions and tenant licensing support it.
- Posture findings appear for the expected provider, subscription, or Microsoft 365 scope.
- First assessment or weekly report can be generated and exported.
- Assistant answers include tenant-specific evidence, source references, and clear caveats when data is missing.
Minimum vs full access path
If customer approval is blocked by permission concerns, start smaller and expand after the first value is proven.
Minimum read-only detection
Start with identity, directory, audit, and reporting permissions. This is usually the lowest-friction customer approval path.
Detection plus enrichment
Add risk, alert, incident, Secure Score, and workload data so triage answers have more evidence.
Detection plus response
Add carefully approved action permissions only when the customer wants ITDR to support containment workflows.
Posture plus remediation
Add cloud posture credentials and remediation planning once baseline ingestion is stable.
First questions to ask the assistant
Use questions like these after connector data and posture findings are available. Good answers should cite evidence and explain what data is missing.
- What should we focus on first across this tenant security posture?
- Which identities should we investigate first and why?
- Where are the largest MFA or conditional access gaps?
- Are our Microsoft and posture connectors healthy?
- Summarize this tenant risk for an executive review.
Completion handoff
Keep this handoff free of raw secrets. Reference the approved vault, ticket, or customer-owned secret channel when credentials are required.
Customer tenant: Microsoft tenant ID: Connector mode: Graph authorization: Office 365 authorization: First sync status: Posture provider: First report generated: Assistant validation prompt: Open issues: