Introduction

The M365 integration enables discovery of the following M365 services, providing visibility into service availability and performance for root cause analysis and remediation:

List of Supported Services
Exchange Online
Mobile Device Management for Office 365
Microsoft Kaizala
Microsoft Teams
Power BI
SharePoint Online
Microsoft Power Automate in Microsoft 365
Sway
Yammer Enterprise
Microsoft Stream
Planner
Azure Information Protection
Power Apps
Microsoft Forms
Microsoft 365 Apps
Microsoft Bookings
Power Apps in Microsoft 365
Microsoft Viva
Skype for Business
Office for the web
Dynamics 365 Apps
Microsoft Power Automate
Microsoft StaffHub
Project Online
OneDrive for Business
Identity Service
Microsoft Defender for Cloud Apps
Microsoft Intune
Project for the web
Microsoft 365 Suite
Microsoft Copilot (Microsoft 365)

After completing the integration installation and set up, Microsoft 365 resources are discovered and monitoring is enabled as specified in the configuration profile.

Supported Metrics

ResourceMetric NameMetric Description
Exchangeoffice365_exchange_MailboxSizeTotalTotal storage consumed by the organization.
office365_exchange_ActiveOrTotalMailboxCountNumber of mailboxes with active count. Active means the user sent/received or read a mail on that day.
office365_exchange_MailboxQuotaLimitCountAs office provides some limit to the usage of mailbox storage. This metric shows the number of mailboxes that have crossed a specific limit. Specifically, under limit, warning issued, send prohibited, send/receive prohibited.
office365_exchange_MessagesTotalSentReadReceivedThe number of messages sent, received, read, or any of these three by the organization in total.
office365_exchange_AppUsageThe number of users of different apps or protocols. The apps are Mail for Mac, Outlook for Mac, Outlook For Windows, Outlook For Mobile, Other For Mobile, Outlook For Web
office365_exchange_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_exchange_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_exchange_ServiceOutageInHoursThe number of hours service has been out of order
SharePointoffice365_sharepoint_UniqueUserCountNumber of unique users who in any way interacted with SharePoint (i.e shared link). The number will be showed in specific activities like
office365_sharepoint_ActiveUserCountThe total number of interactions with SharePoint without respect to the uniqueness of the user.
office365_sharepoint_PageVisitCountThe number of unique pages that the organization has visited.
office365_sharepoint_ActiveFileCountThe number of files that have been interacted with on that day.
office365_sharepoint_TotalFileCountThe total number of files by the organization.
office365_sharepoint_StorageThe total number of pages viewed across all sites
office365_sharepoint_TotalPageVisitCountTotal storage consumption by the organization.
office365_sharepoint_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_sharepoint_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_sharepoint_ServiceOutageInHoursThe number of hours service has been out of order
Yammeroffice365_yammer_InteractionWithMessagesCountNumber of interactions by the organization ie. number of messages likes, posted
office365_yammer_UniqueUserCountInteractingWithMessagesNumber of unique users who interacted with messages ie. number of likes, posted
office365_yammer_UserCountByDeviceTypeNumber of users specifying device type in total ie. web, android etc.
office365_yammer_DailyUserCountByDeviceTypeNumber of users specifying device type on that specific ie. web, android etc.
office365_yammer_GroupCountNumber of groups with active count
office365_yammer_InteractionInGroupsCountNumber of interactions in groups with like/posted/read count
office365_yammer_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_yammer_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_yammer_ServiceOutageInHoursThe number of hours service has been out of order
Microsoft Teamsoffice365_microsoftteams_DailyUniqueUsersByDeviceTypeNumber of activities with teams for the organization with specific activity types. ie number of calls, meetings etc.
office365_microsoftteams_DailyActivitiesByActivityTypeNumber of unique users using teams for the organization with specific activity types. ie number of calls, meetings etc.
office365_microsoftteams_DailyUniqueUsersByActivityTypeNumber of unique users using teams for the organization with specific device types. ie web, android phone etc.
office365_microsoftteams_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_microsoftteams_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_microsoftteams_ServiceOutageInHoursThe number of hours service has been out of order
OneDriveForBusinessoffice365_onedrive_ActiveUserCountThe total number of interactions with OneDrive without respect to the uniqueness of the user.
office365_onedrive_UniqueUserCountNumber of unique users who in any way interacted with OneDrive (i.e shared link). The number will be shown in specific activities like
office365_onedrive_ActiveSiteCountTotal number of sites used by the organization with active count
office365_onedrive_TotalFileCountTotal number of files used by the organization with active count
office365_onedrive_StorageTotal storage consumed by the organization
office365_onedriveforbusiness_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_onedriveforbusiness_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_onedriveforbusiness_ServiceOutageInHoursThe number of hours service has been out of order
OSDPPlatformoffice365_osdpplatform_ActiveUserCountNumber of users who interacted with specific services ie. Exchange OneDrive etc.
office365_osdpplatform_ActiveInactiveUserInServicesCountNumber of users if active or not in specific services ie. Exchange OneDrive etc.
office365_osdpplatform_GroupActivityCountNumber of activities in groups with activity type i.e number of exchange emails recieved
office365_osdpplatform_ActiveGroupCountNumber of total groups with active count
office365_osdpplatform_StorageStorage consumed by the organization.
office365_osdpplatform_FileCountNumber of total files with active count
office365_osdpplatform_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_osdpplatform_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_osdpplatform_ServiceOutageInHoursThe number of hours service has been out of order
OrgLiveIDoffice365_orgliveid_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_orgliveid_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_orgliveid_ServiceOutageInHoursThe number of hours service has been out of order
Lyncoffice365_lync_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_lync_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_lync_ServiceOutageInHoursThe number of hours service has been out of order
DynamicsCRMoffice365_dynamicscrm_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_dynamicscrm_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_dynamicscrm_ServiceOutageInHoursThe number of hours service has been out of order
RMSoffice365_rms_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_rms_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_rms_ServiceOutageInHoursThe number of hours service has been out of order
MobileDeviceManagementoffice365_mobiledevicemanagement_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_mobiledevicemanagement_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_mobiledevicemanagement_ServiceOutageInHoursThe number of hours service has been out of order
Planneroffice365_planner_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_planner_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_planner_ServiceOutageInHoursThe number of hours service has been out of order
SwayEnterpriseoffice365_swayenterprise_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_swayenterprise_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_swayenterprise_ServiceOutageInHoursThe number of hours service has been out of order
PowerBIcomoffice365_powerbicom_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_powerbicom_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_powerbicom_ServiceOutageInHoursThe number of hours service has been out of order
Intuneoffice365_Intune_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_Intune_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_Intune_ServiceOutageInHoursThe number of hours service has been out of order
StaffHuboffice365_staffhub_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_staffhub_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_staffhub_ServiceOutageInHoursThe number of hours service has been out of order
kaizalamessagingservicesoffice365_kaizalamessagingservices_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_kaizalamessagingservices_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_kaizalamessagingservices_ServiceOutageInHoursThe number of hours service has been out of order
Bookingsoffice365_bookings_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_bookings_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_bookings_ServiceOutageInHoursThe number of hours service has been out of order
officeonlineoffice365_officeonline_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_officeonline_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_officeonline_ServiceOutageInHoursThe number of hours service has been out of order
O365Clientoffice365_o365client_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_o365client_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_o365client_ServiceOutageInHoursThe number of hours service has been out of order
PowerAppsoffice365_powerapps_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_powerapps_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_powerapps_ServiceOutageInHoursThe number of hours service has been out of order
PowerAppsM365office365_powerappsm365_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_powerappsm365_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_powerappsm365_ServiceOutageInHoursThe number of hours service has been out of order
MicrosoftFlowoffice365_microsoftflow_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_microsoftflow_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_microsoftflow_ServiceOutageInHoursThe number of hours service has been out of order
MicrosoftFlowM365office365_microsoftflowm365_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_microsoftflowm365_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_microsoftflowm365_ServiceOutageInHoursThe number of hours service has been out of order
Formsoffice365_forms_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_forms_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_forms_ServiceOutageInHoursThe number of hours service has been out of order
ProjectOnlineoffice365_projectonline_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_projectonline_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_projectonline_ServiceOutageInHoursThe number of hours service has been out of order
ProjectForTheWeboffice365_projectfortheweb_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_projectfortheweb_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_projectfortheweb_ServiceOutageInHoursThe number of hours service has been out of order
Streamoffice365_stream_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_stream_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_stream_ServiceOutageInHoursThe number of hours service has been out of order
Vivaoffice365_viva_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_viva_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_viva_ServiceOutageInHoursThe number of hours service has been out of order
cloudappsecurityoffice365_cloudappsecurity_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_cloudappsecurity_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_cloudappsecurity_ServiceOutageInHoursThe number of hours service has been out of order
Microsoft Copilot (Microsoft 365)office365_copilotm365_ServiceStatusService status of service that resembles current operability of the service using a number from 0-16
office365_copilotm365_IncidentCountservice Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count
office365_copilotm365_ServiceOutageInHoursThe number of hours service has been out of order

Register the application with Azure AD

These steps register and authorize a new application to call the reports API.

  1. Log in to the Azure portal using an administrator account.

  2. From the Azure Services menu, Navigate to the App registrations page:

    Image
  3. Select + New Registration.

  4. Enter a display Name and select from the Support account types for who is authorized to access the API:

    Image
  5. Click Register.

  6. On the registration page, save the values in the Application (client) ID and Directory (tenant) ID fields. These are needed later to complete the OpsRamp part of the integration in Step 3: Configure the integration:

    Image

Configure API permissions

Add a Microsoft Graph permission in the left navigation panel, click API permissions to add new permissions for the Microsoft Graph APIs:

Add a Microsoft Graph permission

  1. Click + Add a permission to get a list of commonly used APIs:

    Image
  2. You want to add a permission to the Microsoft Graph API. Select Microsoft Graph:

    Image
  3. Click Application permissions to specify the type of permission needed:

    Image
  4. Select the following permissions:

    PermissionDescription
    User.Read.AllAllows the application to read user profiles and basic company information in your organization.
    Reports.Read.AllAllows the application to read all service usage reports, including Office 365 and Azure Active Directory, without a signed-in user.
    ServiceHealth.Read.AllAllows the application to read your tenant's service health information, including service issues and health overviews, without a signed-in user.
  5. Go to the API Permissions page and grant permission for all configured permissions by selecting Grant admin consent for xyz:

    Image

Add a client secret

  1. In the left navigation panel, click Certificates & secrets:

    Image
  2. Select + New client secret.

    Image
  3. Add a Description and select a time duration for when the secret Expires:

    Image
  4. Click Add.

  5. Save the Value and Secret ID. These are needed later to complete the OpsRamp part of the integration while configuring the integration.

    Image

Configure the integration

  1. From All Clients, select a client.

  2. Navigate to Setup > Account.

  3. Select the Integrations and Apps tab.

  4. The Installed Integrations page, where all the installed applications are displayed. If there are no installed applications, it will navigate to the Available Integrations and Apps page.

  5. Click + ADD on the Installed Integrations page. The Available Integrations and Apps page displays all the available applications along with the newly created application with the version.
    Note: Search for the application using the search option available. Alternatively, use the All Categories option to search.

  6. Click ADD under Office365:

  7. In Add OFFICE365 page, enter account information:

    Image
    PropertyDescription
    Name(required) User-defined, descriptive integration name.
    Subscription Id(required) Azure subscription ID, from Azure services > Subscriptions.
    Client ID(required) OpsRamp client ID saved.
    Tenant ID(required) OpsRamp tenant ID saved.
    Security Key(required) Client secret ID saved.
    Confirm Security Key(required) Re Enter the Security Key.
    Enable Optimized Monitoring Mode (Recommended)Toggle to enable integration-level monitoring using bulk API calls. Optimized to handle large-scale dataset and minimize rate-limiting issues. See Microsoft 365 Integration-Level Monitoring for more details.
    Monitoring Frequency (minutes)Visible when Optimized Monitoring Mode is enabled. Select the frequency for integration-level metric collection. Options: 5, 10, 15, 30, 60, 120, 1440.
    PERFORM ACTIONS
    Generate Alerts for Service IncidentsWhen enabled, automatically generates alerts when Office 365 service incidents are detected for monitored services.
    Frequency (in Minutes)Visible when "Generate Alerts for Service Incidents" is enabled. Select the polling frequency for incident alert checks.
  8. Click Next.In the RESOURCE TYPE section, select:

    • ALL: All the existing and future resources will be discovered.
    • SELECT: You can select one or multiple resources to be discovered.
  9. In the DISCOVERY SCHEDULE section, select Recurrence Pattern to add one of the following patterns:

    • Minutes
    • Hourly
    • Daily
    • Weekly
    • Monthly
      Image
  10. Click Finish.
    The application is now installed and displayed on the Installed Integration page. Use the search field to find the installed application.

Risks, Limitations & Assumptions

The availability is shown unknown for few resources even if it is enabled on the respective resource metrics. This is because of the presence of multiple native type resources under the same resource type.

Probable list of health statuses

Health Status from APIDescriptionService status shown in OpsRamp portal
InvestigatingA potential issue was identified by Microsoft and information is being gathered about the issue and the scope of impact.0
ServiceDegradationMicrosoft has confirmed that there is an issue that may affect use of a service or feature. You might see this status if a service is performing more slowly than usual, there are intermittent interruptions, or if a feature is not working.1
ServiceInterruptionYou will see this status if Microsoft determines that an issue affects the ability for users to access the service. In this case, the issue is significant and can be reproduced consistently.2
RestoringServiceThe cause of the issue has been identified by Microsoft and action is being taken to bring the service back to a healthy state.3
ExtendedRecoveryThis status indicates that corrective action is in progress to restore service to most users but will take some time to reach all the affected systems. You might also see this status if Microsoft has made a temporary fix to reduce impact while Microsoft waits to apply a permanent fix.4
InvestigationSuspendedYou will see this status if Microsoft's detailed investigation of a potential issue results in a request for additional information from customers to allow us to investigate further. If Microsoft needs you to take action, you will be notified about what data or logs Microsoft needs.5
ServiceRestoredMicrosoft has confirmed that corrective action has resolved the underlying problem and the service has been restored to a healthy state. View the issue details to find out what went wrong.6
PostIncidentReviewPublishedMicrosoft has published a post-incident report for a specific issue that includes root cause information and next steps to ensure a similar issue does not reoccur.7
FalsePositiveAfter a detailed investigation, Microsoft has confirmed the service is healthy and operating as designed. No impact to the service was observed or the cause of the incident originated outside of the service.8
ServiceOperationalService features are healthy and running smoothly.9
VerifyingServiceThe action has been taken to mitigate the issue and verified that the service is healthy.10
ResolvedReserved for future use.11
MitigatedExternalReserved for future use.12
MitigatedReserved for future use.13
ResolvedExternalReserved for future use.14
ConfirmedReserved for future use.15
ReportedReserved for future use.16

See serviceHealthStatus values for more details.