Introduction
The M365 integration enables discovery of the following M365 services, providing visibility into service availability and performance for root cause analysis and remediation:
| List of Supported Services |
|---|
| Exchange Online |
| Mobile Device Management for Office 365 |
| Microsoft Kaizala |
| Microsoft Teams |
| Power BI |
| SharePoint Online |
| Microsoft Power Automate in Microsoft 365 |
| Sway |
| Yammer Enterprise |
| Microsoft Stream |
| Planner |
| Azure Information Protection |
| Power Apps |
| Microsoft Forms |
| Microsoft 365 Apps |
| Microsoft Bookings |
| Power Apps in Microsoft 365 |
| Microsoft Viva |
| Skype for Business |
| Office for the web |
| Dynamics 365 Apps |
| Microsoft Power Automate |
| Microsoft StaffHub |
| Project Online |
| OneDrive for Business |
| Identity Service |
| Microsoft Defender for Cloud Apps |
| Microsoft Intune |
| Project for the web |
| Microsoft 365 Suite |
| Microsoft Copilot (Microsoft 365) |
After completing the integration installation and set up, Microsoft 365 resources are discovered and monitoring is enabled as specified in the configuration profile.
Supported Metrics
| Resource | Metric Name | Metric Description |
|---|---|---|
| Exchange | office365_exchange_MailboxSizeTotal | Total storage consumed by the organization. |
| office365_exchange_ActiveOrTotalMailboxCount | Number of mailboxes with active count. Active means the user sent/received or read a mail on that day. | |
| office365_exchange_MailboxQuotaLimitCount | As office provides some limit to the usage of mailbox storage. This metric shows the number of mailboxes that have crossed a specific limit. Specifically, under limit, warning issued, send prohibited, send/receive prohibited. | |
| office365_exchange_MessagesTotalSentReadReceived | The number of messages sent, received, read, or any of these three by the organization in total. | |
| office365_exchange_AppUsage | The number of users of different apps or protocols. The apps are Mail for Mac, Outlook for Mac, Outlook For Windows, Outlook For Mobile, Other For Mobile, Outlook For Web | |
| office365_exchange_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 | |
| office365_exchange_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_exchange_ServiceOutageInHours | The number of hours service has been out of order | |
| SharePoint | office365_sharepoint_UniqueUserCount | Number of unique users who in any way interacted with SharePoint (i.e shared link). The number will be showed in specific activities like |
| office365_sharepoint_ActiveUserCount | The total number of interactions with SharePoint without respect to the uniqueness of the user. | |
| office365_sharepoint_PageVisitCount | The number of unique pages that the organization has visited. | |
| office365_sharepoint_ActiveFileCount | The number of files that have been interacted with on that day. | |
| office365_sharepoint_TotalFileCount | The total number of files by the organization. | |
| office365_sharepoint_Storage | The total number of pages viewed across all sites | |
| office365_sharepoint_TotalPageVisitCount | Total storage consumption by the organization. | |
| office365_sharepoint_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 | |
| office365_sharepoint_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_sharepoint_ServiceOutageInHours | The number of hours service has been out of order | |
| Yammer | office365_yammer_InteractionWithMessagesCount | Number of interactions by the organization ie. number of messages likes, posted |
| office365_yammer_UniqueUserCountInteractingWithMessages | Number of unique users who interacted with messages ie. number of likes, posted | |
| office365_yammer_UserCountByDeviceType | Number of users specifying device type in total ie. web, android etc. | |
| office365_yammer_DailyUserCountByDeviceType | Number of users specifying device type on that specific ie. web, android etc. | |
| office365_yammer_GroupCount | Number of groups with active count | |
| office365_yammer_InteractionInGroupsCount | Number of interactions in groups with like/posted/read count | |
| office365_yammer_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 | |
| office365_yammer_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_yammer_ServiceOutageInHours | The number of hours service has been out of order | |
| Microsoft Teams | office365_microsoftteams_DailyUniqueUsersByDeviceType | Number of activities with teams for the organization with specific activity types. ie number of calls, meetings etc. |
| office365_microsoftteams_DailyActivitiesByActivityType | Number of unique users using teams for the organization with specific activity types. ie number of calls, meetings etc. | |
| office365_microsoftteams_DailyUniqueUsersByActivityType | Number of unique users using teams for the organization with specific device types. ie web, android phone etc. | |
| office365_microsoftteams_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 | |
| office365_microsoftteams_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_microsoftteams_ServiceOutageInHours | The number of hours service has been out of order | |
| OneDriveForBusiness | office365_onedrive_ActiveUserCount | The total number of interactions with OneDrive without respect to the uniqueness of the user. |
| office365_onedrive_UniqueUserCount | Number of unique users who in any way interacted with OneDrive (i.e shared link). The number will be shown in specific activities like | |
| office365_onedrive_ActiveSiteCount | Total number of sites used by the organization with active count | |
| office365_onedrive_TotalFileCount | Total number of files used by the organization with active count | |
| office365_onedrive_Storage | Total storage consumed by the organization | |
| office365_onedriveforbusiness_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 | |
| office365_onedriveforbusiness_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_onedriveforbusiness_ServiceOutageInHours | The number of hours service has been out of order | |
| OSDPPlatform | office365_osdpplatform_ActiveUserCount | Number of users who interacted with specific services ie. Exchange OneDrive etc. |
| office365_osdpplatform_ActiveInactiveUserInServicesCount | Number of users if active or not in specific services ie. Exchange OneDrive etc. | |
| office365_osdpplatform_GroupActivityCount | Number of activities in groups with activity type i.e number of exchange emails recieved | |
| office365_osdpplatform_ActiveGroupCount | Number of total groups with active count | |
| office365_osdpplatform_Storage | Storage consumed by the organization. | |
| office365_osdpplatform_FileCount | Number of total files with active count | |
| office365_osdpplatform_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 | |
| office365_osdpplatform_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_osdpplatform_ServiceOutageInHours | The number of hours service has been out of order | |
| OrgLiveID | office365_orgliveid_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_orgliveid_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_orgliveid_ServiceOutageInHours | The number of hours service has been out of order | |
| Lync | office365_lync_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_lync_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_lync_ServiceOutageInHours | The number of hours service has been out of order | |
| DynamicsCRM | office365_dynamicscrm_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_dynamicscrm_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_dynamicscrm_ServiceOutageInHours | The number of hours service has been out of order | |
| RMS | office365_rms_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_rms_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_rms_ServiceOutageInHours | The number of hours service has been out of order | |
| MobileDeviceManagement | office365_mobiledevicemanagement_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_mobiledevicemanagement_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_mobiledevicemanagement_ServiceOutageInHours | The number of hours service has been out of order | |
| Planner | office365_planner_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_planner_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_planner_ServiceOutageInHours | The number of hours service has been out of order | |
| SwayEnterprise | office365_swayenterprise_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_swayenterprise_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_swayenterprise_ServiceOutageInHours | The number of hours service has been out of order | |
| PowerBIcom | office365_powerbicom_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_powerbicom_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_powerbicom_ServiceOutageInHours | The number of hours service has been out of order | |
| Intune | office365_Intune_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_Intune_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_Intune_ServiceOutageInHours | The number of hours service has been out of order | |
| StaffHub | office365_staffhub_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_staffhub_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_staffhub_ServiceOutageInHours | The number of hours service has been out of order | |
| kaizalamessagingservices | office365_kaizalamessagingservices_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_kaizalamessagingservices_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_kaizalamessagingservices_ServiceOutageInHours | The number of hours service has been out of order | |
| Bookings | office365_bookings_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_bookings_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_bookings_ServiceOutageInHours | The number of hours service has been out of order | |
| officeonline | office365_officeonline_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_officeonline_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_officeonline_ServiceOutageInHours | The number of hours service has been out of order | |
| O365Client | office365_o365client_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_o365client_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_o365client_ServiceOutageInHours | The number of hours service has been out of order | |
| PowerApps | office365_powerapps_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_powerapps_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_powerapps_ServiceOutageInHours | The number of hours service has been out of order | |
| PowerAppsM365 | office365_powerappsm365_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_powerappsm365_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_powerappsm365_ServiceOutageInHours | The number of hours service has been out of order | |
| MicrosoftFlow | office365_microsoftflow_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_microsoftflow_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_microsoftflow_ServiceOutageInHours | The number of hours service has been out of order | |
| MicrosoftFlowM365 | office365_microsoftflowm365_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_microsoftflowm365_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_microsoftflowm365_ServiceOutageInHours | The number of hours service has been out of order | |
| Forms | office365_forms_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_forms_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_forms_ServiceOutageInHours | The number of hours service has been out of order | |
| ProjectOnline | office365_projectonline_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_projectonline_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_projectonline_ServiceOutageInHours | The number of hours service has been out of order | |
| ProjectForTheWeb | office365_projectfortheweb_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_projectfortheweb_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_projectfortheweb_ServiceOutageInHours | The number of hours service has been out of order | |
| Stream | office365_stream_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_stream_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_stream_ServiceOutageInHours | The number of hours service has been out of order | |
| Viva | office365_viva_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_viva_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_viva_ServiceOutageInHours | The number of hours service has been out of order | |
| cloudappsecurity | office365_cloudappsecurity_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_cloudappsecurity_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_cloudappsecurity_ServiceOutageInHours | The number of hours service has been out of order | |
| Microsoft Copilot (Microsoft 365) | office365_copilotm365_ServiceStatus | Service status of service that resembles current operability of the service using a number from 0-16 |
| office365_copilotm365_IncidentCount | service Incident Count that clarifies the number of log entries by Microsoft for specific reasons. Provided information: resolved count, pending count, total count | |
| office365_copilotm365_ServiceOutageInHours | The number of hours service has been out of order |
Register the application with Azure AD
These steps register and authorize a new application to call the reports API.
Log in to the Azure portal using an administrator account.
From the Azure Services menu, Navigate to the App registrations page:

Select + New Registration.
Enter a display Name and select from the Support account types for who is authorized to access the API:

Click Register.
On the registration page, save the values in the Application (client) ID and Directory (tenant) ID fields. These are needed later to complete the OpsRamp part of the integration in Step 3: Configure the integration:

Configure API permissions
Add a Microsoft Graph permission in the left navigation panel, click API permissions to add new permissions for the Microsoft Graph APIs:
Add a Microsoft Graph permission
Click + Add a permission to get a list of commonly used APIs:

You want to add a permission to the Microsoft Graph API. Select Microsoft Graph:

Click Application permissions to specify the type of permission needed:

Select the following permissions:
Permission Description User.Read.All Allows the application to read user profiles and basic company information in your organization. Reports.Read.All Allows the application to read all service usage reports, including Office 365 and Azure Active Directory, without a signed-in user. ServiceHealth.Read.All Allows the application to read your tenant's service health information, including service issues and health overviews, without a signed-in user. Go to the API Permissions page and grant permission for all configured permissions by selecting Grant admin consent for xyz:

Add a client secret
In the left navigation panel, click Certificates & secrets:

Select + New client secret.

Add a Description and select a time duration for when the secret Expires:

Click Add.
Save the Value and Secret ID. These are needed later to complete the OpsRamp part of the integration while configuring the integration.

Configure the integration
From All Clients, select a client.
Navigate to Setup > Account.
Select the Integrations and Apps tab.
The Installed Integrations page, where all the installed applications are displayed. If there are no installed applications, it will navigate to the Available Integrations and Apps page.
Click + ADD on the Installed Integrations page. The Available Integrations and Apps page displays all the available applications along with the newly created application with the version.
Note: Search for the application using the search option available. Alternatively, use the All Categories option to search.Click ADD under Office365:

In Add OFFICE365 page, enter account information:

Property Description Name (required) User-defined, descriptive integration name. Subscription Id (required) Azure subscription ID, from Azure services > Subscriptions. Client ID (required) OpsRamp client ID saved. Tenant ID (required) OpsRamp tenant ID saved. Security Key (required) Client secret ID saved. Confirm Security Key (required) Re Enter the Security Key. Enable Optimized Monitoring Mode (Recommended) Toggle to enable integration-level monitoring using bulk API calls. Optimized to handle large-scale dataset and minimize rate-limiting issues. See Microsoft 365 Integration-Level Monitoring for more details. Monitoring Frequency (minutes) Visible when Optimized Monitoring Mode is enabled. Select the frequency for integration-level metric collection. Options: 5, 10, 15, 30, 60, 120, 1440. PERFORM ACTIONS Generate Alerts for Service Incidents When enabled, automatically generates alerts when Office 365 service incidents are detected for monitored services. Frequency (in Minutes) Visible when "Generate Alerts for Service Incidents" is enabled. Select the polling frequency for incident alert checks. Click Next.In the RESOURCE TYPE section, select:
- ALL: All the existing and future resources will be discovered.
- SELECT: You can select one or multiple resources to be discovered.
In the DISCOVERY SCHEDULE section, select Recurrence Pattern to add one of the following patterns:
- Minutes
- Hourly
- Daily
- Weekly
- Monthly

Click Finish.The application is now installed and displayed on the Installed Integration page. Use the search field to find the installed application.
Risks, Limitations & Assumptions
The availability is shown unknown for few resources even if it is enabled on the respective resource metrics. This is because of the presence of multiple native type resources under the same resource type.
Probable list of health statuses
| Health Status from API | Description | Service status shown in OpsRamp portal |
|---|---|---|
| Investigating | A potential issue was identified by Microsoft and information is being gathered about the issue and the scope of impact. | 0 |
| ServiceDegradation | Microsoft has confirmed that there is an issue that may affect use of a service or feature. You might see this status if a service is performing more slowly than usual, there are intermittent interruptions, or if a feature is not working. | 1 |
| ServiceInterruption | You will see this status if Microsoft determines that an issue affects the ability for users to access the service. In this case, the issue is significant and can be reproduced consistently. | 2 |
| RestoringService | The cause of the issue has been identified by Microsoft and action is being taken to bring the service back to a healthy state. | 3 |
| ExtendedRecovery | This status indicates that corrective action is in progress to restore service to most users but will take some time to reach all the affected systems. You might also see this status if Microsoft has made a temporary fix to reduce impact while Microsoft waits to apply a permanent fix. | 4 |
| InvestigationSuspended | You will see this status if Microsoft's detailed investigation of a potential issue results in a request for additional information from customers to allow us to investigate further. If Microsoft needs you to take action, you will be notified about what data or logs Microsoft needs. | 5 |
| ServiceRestored | Microsoft has confirmed that corrective action has resolved the underlying problem and the service has been restored to a healthy state. View the issue details to find out what went wrong. | 6 |
| PostIncidentReviewPublished | Microsoft has published a post-incident report for a specific issue that includes root cause information and next steps to ensure a similar issue does not reoccur. | 7 |
| FalsePositive | After a detailed investigation, Microsoft has confirmed the service is healthy and operating as designed. No impact to the service was observed or the cause of the incident originated outside of the service. | 8 |
| ServiceOperational | Service features are healthy and running smoothly. | 9 |
| VerifyingService | The action has been taken to mitigate the issue and verified that the service is healthy. | 10 |
| Resolved | Reserved for future use. | 11 |
| MitigatedExternal | Reserved for future use. | 12 |
| Mitigated | Reserved for future use. | 13 |
| ResolvedExternal | Reserved for future use. | 14 |
| Confirmed | Reserved for future use. | 15 |
| Reported | Reserved for future use. | 16 |
See serviceHealthStatus values for more details.










