Skip to content
Sam360 Logo Sam360 Logo Sam360 Logo
  • Support
    • Documentation
    • Submit Ticket
  • Contact
  • Support
    • Documentation
    • Submit Ticket
  • Contact

Introduction

  • Overview
  • Collecting Inventory
  • Software Metering
  • What Data Is Collected?
  • Data Security
  • Quick Start Guide (Software Baseline Clients)

Portal

Introduction
  • Grid – Quick Filters
  • Notes – Markdown Guide
  • Grid – Introduction
Configuration
  • Forgot Your Password
  • Reset User Password
  • Add Portal User
  • Grant Portal Access To Existing User
  • Manage Client Permissions
Sample Reports
  • CyberSecurity Excel Overview
Importing/Exporting Data
  • Import Inventory And License Data
  • Import Device Data (CSV file)
  • Import Software Inventory Data (CSV file)
  • Import VMware Data
  • Import SCCM Data
  • Import Hyper-V Data
  • Import Office 365 Data
  • Import Sam360 Inventory Data (s3tools)
  • Import License Data
  • Exporting To Microsoft Universal Inventory

Data Collection

Management Point
  • Sam360 Management Point Introduction
  • Install Management Point
  • Management Point Service Account Requirements
  • How the Remote Scan works
  • Start Management Point Configuration Tool
  • 3rd Party & Cloud Integration
    • VMware Integration
    • XenServer Integration
    • Microsoft 365 Integration
    • Install/Update Required PowerShell Modules
    Technical Notes
    • Management Point Footprint
    • Improve Remote Scan Coverage
    • Configure Windows Firewall with Group Policy
    • Disable Communication With Sam360 Servers
    • Inspecting Inventory Data
    • Management Point Change Log
    • Update Management Point Credentials
Agent
  • Sam360 Agent Introduction
  • Deploy Agent Manually
  • Deploy Agent with Group Policy
  • Deploy Agent Using Management Point
  • Enable logging
  • Locate Sam360 Discovery Agent Log Files
  • Agent and Management Point Proxy
Web Scan
  • Sam360 Web Scan Introduction
  • Upload Inventory Data Files To Sam360
  • Gather Inventory From Offline Networks
  • Gather Inventory From An Offline Computer
  • Export List Of Devices From Active Directory

Data Model

  • Overview
Hardware
  • ActiveSync Device
  • Device
  • Terminal Device
  • Wireless Network
  • Network Card
  • Logical Drive
  • Physical Drive
Licensing
  • Agreement
  • Contact
  • License Position Record
  • License
Software
  • Application File Instance
  • Application File
  • Product
  • Product Installation
  • SQL Server Instance
  • Vendor
Settings
  • Rule
  • Client File
  • Entity History Event
  • Management Point
  • Management Point Task
  • Product Name Modifier
  • Report
  • Tenant
  • Report Task
Usage
  • Software Usage Record
  • Document
  • Hourly Software Usage Record
  • Netstat Connection
  • Performance Snapshot
  • IP Address
Configuration
  • Exchange Server Instance
  • Group
  • Web Application
  • OEM Warranty
  • Security Info Product
  • Site Collection
  • Site
  • SQL Server Database
  • SQL Server Service
  • User Permission
  • Web Site
  • Windows Domain
  • Windows Service
  • Windows Update
  • Device Certificate
  • Device VPN
  • Security Product Info
  • IIS Web Application
Users
  • User
Cloud
  • Azure Tenant
  • Azure Sign In Audit Log
  • Azure Application
  • Azure Sign In Auth Method
  • Home
  • Support Documentation
  • Data Collection
  • Management Point
  • 3rd Party & Cloud Integration
  • Microsoft 365 Integration

Sam360 integrates with Microsoft 365 by importing the following data points once per day

  • Tenant details
  • Directory, user & device information
  • Subscription entitlement and allocation information
  • Usage data
  • Sign in audit logs

To import this information, Sam360 creates an App Principal in the target Azure AD environment. The App Principal is configured with the following permissions

  • Microsoft Graph -> User.Read.All
  • Microsoft Graph -> Reports.Read.All
  • Microsoft Graph -> Device.Read.All
  • Microsoft Graph -> Directory.Read.All
  • Microsoft Graph -> Organization.Read.All
  • Microsoft Graph -> AuditLog.Read.All

A dedicated service principal is also created in the target Azure AD environment. The UPN of the service principal is called ‘Sam360IntegrationAccount@domain’ where ‘domain’ is the primary domain name of the Microsoft 365 tenant (e.g. Sam360IntegrationAccount@contoso.com) The service principal is added to the following administrator roles

  • ‘Service Support Administrator’
  • ‘View-Only Organization Management’

The App Principal key and Service Principal password are stored securely locally on the Management Point device. They are never transmitted to Sam360 servers. Both App and service principals can be disabled or deleted at any time in the target Azure AD environment.

To configure Microsoft 365 integration…

  1. Ensure that the required PowerShell modules are installed. Instructions here.
  2. Ensure that the Management Point user account can access the following URLs
    • login.microsoftonline.com:443
    • aadcdn.msauth.net:443
    • graph.windows.net:443
    • graph.microsoft.com:443
    • ps.outlook.com:443
  3. Start the Management Point configuration tool. Instructions here.
  4. Click ‘Tasks’
  5. Click ‘Add Task’, ‘Cloud Service’, then ‘Office 365’
  6. Click ‘Set Up Office 365 Integration’
  7. A PowerShell script will execute in the background to create the App and Service Principals. The script will prompt for the credentials on an Microsoft 365 Tenant Administrator account up to 3 times The same account details should be used each time. These account details are not stored.
  8. Click ‘Test Settings’ to verify that the integration has been configured correctly.
  9. Click OK. The Management Point will connect to the Microsoft 365 service using the specified credentials and import all licensing relevant information.

By default, the Microsoft 365 reporting API anonymises application and services usage information. If usage data is anonymised, Sam360 can not determine which users are active or using their allocated subscriptions. Report data anonymisation is documented in this Microsoft support article. To disable anonymisation

  1. Go to the Microsoft 365 admin center.
  2. Go to Settings > Org Settings > Services.
  3. Select Reports.
  4. Clear Display concealed user, group, and site names in all reports, and then select Save.

The Sam360 Management Point uses the Office 365 integration PowerShell script from the open source SAM Gold Toolkit to query the Microsoft 365 service. The script does not make any changes to the Microsoft 365 environment – it only reads information.

Rate This Article :
Share This Article :
  • Facebook
  • Twitter
  • LinkedIn
  • Pinterest
Updated on March 28, 2022

Leave A Comment Cancel reply

Partner First

Enabling data driven IT projects
  • Download

Get Support

    support@sam360.com
    Mon-Fri: 09:00 – 18:00 UTC
  • +353 1 566 6390‬

Find Us

NCI Research Centre, IFSC Dublin 1, Ireland
  • Check maps
© Copyright 2012 - | Sam360 | All Rights Reserved
TwitterLinkedInEmail