Get started
Connect Microsoft 365
Add the Microsoft 365 connector in Integrations so DSAR Respond can search your organisation's data.
What this task achieves
The Microsoft 365 connector lets DSAR Respond search your organisation's Exchange mailboxes, OneDrive files, and SharePoint documents from inside a case, instead of asking colleagues to search their own mailboxes and send you what they find. Once it is connected, the Discovery tab appears on cases and the results are added to the case automatically, ready for review and redaction.
Microsoft 365 is the only connector DSAR Respond offers. Anything it cannot reach still has to be added to a case by hand, which is covered in Add and organise documents.
Before you begin
- You need the Admin role. Members can see the Integrations page and a connector's health, but cannot add, test, or disconnect one, and Viewers do not see the page at all.
- Data connectors are available on the Growth and Pro plans. On other plans the Integrations page shows a message to that effect instead of the connect button.
- You need to sign in to Microsoft with an account that can grant organisation-wide admin consent for your tenant. If that is not you, arrange for the person who can to be at the keyboard for step 5 — the authorisation cannot be handed over part way through.
- Decide in advance which Microsoft 365 tenant is the right one. The connector is bound to the tenant you consent in.
Review what the connector can read
DSAR Respond asks for four Microsoft Graph permissions, listed in the wizard before you authorise anything:
| Permission | What it allows |
|---|---|
Mail.Read | Read emails from Exchange |
Files.Read.All | Read files from OneDrive |
Sites.Read.All | Read documents from SharePoint |
User.Read.All | Read user directory information |
These are read-only, and they are granted at the organisation level across your whole tenant — not for a chosen list of mailboxes or sites. There is no per-mailbox or per-site picker anywhere in the product. What limits an individual search is the scope you set on the case: the sources, search terms, and date range you choose when you start a discovery run.
UK GDPR context
Connecting the tenant is a significant decision about access to personal data, not just a piece of configuration, and it is worth recording alongside your organisation's other security decisions. It does not change what you may lawfully search: each search still has to be reasonable and proportionate to the request in front of you, and you must be able to show what you did and why. Granting broad read access does not oblige you to search everything, and it does not by itself justify searching everything. Set the scope of each run on the case, and record your reasoning there — see Find data with Microsoft 365.
This is operational guidance for UK organisations, not legal advice.
Add the connector
- Select Integrations in the sidebar.
- Select Connect Data Source. If no connector exists yet, the page shows No integrations connected yet with the same button. The Connect Data Source wizard opens at Step 1 of 4.
- Under Choose a data source, select Microsoft 365 — described as Connect Exchange, OneDrive, and SharePoint — then select Next.
- On Review permissions, read the four permissions listed above and the Admin consent required notice. Tick I understand these permissions will be granted at the organisation level, then select Next. You cannot continue until the box is ticked.
- On the
Authorize accessstep, selectAuthorize with Microsoft. DSAR Respond hands you to Microsoft to sign in and grant consent for your organisation. - Complete the sign-in and consent at Microsoft. You are returned to DSAR Respond, which confirms Microsoft 365 connected successfully and shows the connector and the date and time it was authorised.
- Select Go to Integrations to close the wizard. The connector now appears as a card on the page.
Use Back to revisit a step, or Cancel to leave the wizard without connecting. Nothing is created until you complete the consent at Microsoft.
Important
Complete the wizard in one pass. The authorisation link is short-lived and single-use: leaving it part way through, reusing a browser tab, or signing in to a different tenant produces an error and you have to start again. Never share the Microsoft consent link, and never send it, a tenant identifier, or any credential by email.
Check the connector after connecting
Each connector appears on Integrations as a card showing its name, its status, and when it was last tested.
| Status | What it means |
|---|---|
| Connected | The connector is authorised and ready for discovery. |
| Pending | Authorisation has not finished. |
| Disconnected | The connector is no longer authorised. |
| Error | The last check failed. Discovery will not work until it is resolved. |
Select Test Connection to check it now. A successful test reports Connection test successful and updates Last tested; a failure reports Connection test failed: followed by the reason. Test it as soon as you connect — that confirms the consent actually applies, before someone relies on it in the middle of a case.
Connect during first-time setup
Step 3 of 4 of the setup wizard is also called Connect Microsoft 365, and its button takes you through Microsoft consent for a connector that already exists. If you have not created one yet, the step reports that no Microsoft 365 connector is configured and asks you to set one up in Integrations first. Either complete the Connect Data Source wizard on the Integrations page as above, or select Skip this step and come back — nothing else in setup depends on it.
Disconnect or replace a connector
Your organisation can hold one connector of each type at a time, so replacing the Microsoft 365 connector means disconnecting the existing one first.
- On the connector card, select Disconnect.
- Confirm in the Disconnect Microsoft 365? dialog. It warns that discovery jobs will no longer work until you reconnect.
- To connect again, run Connect Data Source from the start and grant admin consent afresh.
There is no reconnect button
The connector card offers only Test Connection and Disconnect. A connector stuck at Error — for example after the grant was revoked or credentials were rotated in Microsoft Entra — cannot be repaired in place: disconnect it and run the wizard again. Discovery runs already completed keep their results, but no new run will work until a connector is connected.
If connecting fails
Failures in the wizard appear as Failed to connect Microsoft 365 with the reason after the colon. The most common causes are that admin consent was declined, that the signed-in account cannot consent for the whole tenant, that you signed in to a different tenant, that the authorisation link timed out or was reused, or that a connector of this type already exists.
Troubleshoot the core workflow lists each message with the fix, along with the connection-test failures and the discovery error codes that follow from a connector problem. If a failure persists after you have worked through it, contact product support with the exact wording — and nothing else from the case.
Official sources
What happens next
What happens next
Setup is complete. Continue to the Access-request lifecycle overview to follow a request from intake to closure, or go straight to Find data with Microsoft 365 to see how the connector is used on a case.
Last reviewed . UK regulatory context.