M3
LivePro

Microsoft 365

ProductivityBuilt by cAND/or OAuth 2.0 Setup: ~10 minutes Includes Client Management

Connect Helix to Microsoft 365 for calendar sync, Outlook integration, and Teams notifications. Appointment scheduling syncs with Outlook. Tech availability imports from personal calendar blocks.

Your Organization

Connect Helix to your own Microsoft 365 account. Applies to all users in your MSP — calendar sync, notifications, and staff tools.

Required Credentials

2 fields
Microsoft 365 AccountClick to Connect

Click Connect with Microsoft in the App Marketplace. An admin-level Microsoft 365 account is required to grant calendar and contacts permissions for your organization.

Tenant ID
Optional

Optional override. Found in Microsoft Entra ID → Overview. Auto-populated from the OAuth flow in most cases.

Format:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
Enables →
outlook_calendar_syncteams_notificationscontacts_sync

Data Flow

3 capabilities
Helix initiates
Vendor notifies Helix
Both directions
// Helix → VendorHelix initiates

Teams Notifications

Helix → Vendor

Ticket and appointment notifications delivered to Teams channels

ProtocolREST API call via Microsoft Graph
TriggerConfigurable: ticket created, ticket escalated, appointment approaching, contract signed
AuthOAuth 2.0 (application-level)
You configureNo configuration needed in Teams beyond the OAuth connection.
Helix doesConfigure target Teams channels in App Marketplace → Microsoft 365 → Notifications. Different event types can route to different channels.

Contacts Sync

Helix → Vendor

Client contacts synced from Outlook contacts

ProtocolREST API call (read-only)
TriggerOn-demand import. Technician initiates from Helix Settings → Contacts → Import from Outlook.
AuthOAuth 2.0 (user-level)
You configureNo configuration needed in Outlook.
Helix doesContacts are imported into the connected company record in Helix. Duplicates are flagged for review.
// BidirectionalBoth sides communicate

Outlook Calendar Sync

Bidirectional

Helix appointments sync to Outlook. Personal calendar blocks import as unavailable time.

ProtocolOAuth 2.0 API (both directions)
TriggerAppointment created or updated in Helix syncs immediately to Outlook. Personal calendar blocks sync to Helix on a 15-minute schedule.
AuthOAuth 2.0 (user-level, per technician)
You configureEach technician connects their own Microsoft account in Helix Settings → My Profile → Calendar. Admin consent must be granted first during the initial connection.
Helix doesHelix creates Outlook calendar events for appointments. Personal blocks appear as unavailable time in the dispatch board without exposing personal details.

Client Management

MSP Feature

Connect your clients' Microsoft 365 tenants to manage them directly from their Helix client record — without opening the vendor's admin console. Each client gets their own separate connection.

Required Credentials

4 fields
Client Tenant ID
Required

The Microsoft 365 tenant ID for the client. Found in Microsoft Entra ID → Overview when signed into the client tenant, or in Microsoft Partner Center → Customers → [Client] → Account.

Format:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
Enables →
user_provisioninguser_deprovisioningpassword_resetlicense_managementmfa_reportingsecurity_alerts
GDAP Relationship ID
Optional

Granular Delegated Admin Privilege relationship ID. Found in Microsoft Partner Center → Customers → [Client] → Admin relationships. Preferred method — grants scoped, time-bounded admin access without permanent global admin privileges in the client tenant.

Format:GDAP-••••••••••••••••
Use GDAP where available. It is the Microsoft-recommended partner access model and limits blast radius if credentials are compromised.
Enables →
user_provisioninguser_deprovisioningpassword_resetlicense_managementmfa_reportingsecurity_alerts
Service Account UPN
Optional

Alternative to GDAP. UPN of a dedicated service account created in the client tenant with User Administrator and License Administrator roles assigned. Use when GDAP is not yet established for this client.

Format:helix-admin@clientdomain.onmicrosoft.com
Enables →
user_provisioninguser_deprovisioningpassword_resetlicense_management
Service Account Password
OptionalSecret

Password for the service account above. Required only when authenticating via service account rather than GDAP.

Format:••••••••••••••••
Enables →
user_provisioninguser_deprovisioningpassword_resetlicense_management

Data Flow

6 capabilities
Helix initiates
Vendor notifies Helix
Both directions
// Helix → VendorHelix initiates

User Provisioning

Helix → Vendor

Create users, assign licenses, and configure MFA in the client tenant from Helix onboarding workflows

ProtocolREST API call via Microsoft Graph
TriggerOnboarding ticket reaches provisioning milestone, or tech initiates from client record → Microsoft 365 tab
AuthGDAP (preferred) or service account credentials
You configureGDAP: Establish a GDAP relationship in Partner Center with at minimum User Administrator and License Administrator roles. Service account: Create an account in the client tenant with those roles assigned.
Helix doesProvisioning templates are configurable per client in the client record. Helix creates the user, assigns the specified license SKU, and enforces MFA policy in a single workflow step.

User Deprovisioning

Helix → Vendor

Disable accounts, revoke licenses, wipe enrolled devices, and block sign-in for departing users

ProtocolREST API call via Microsoft Graph
TriggerOffboarding ticket reaches deprovisioning milestone, or tech initiates from client record → Microsoft 365 tab → [User] → Deprovision
AuthGDAP (preferred) or service account credentials
You configureNo additional configuration beyond provisioning setup.
Helix doesHelix executes each offboarding step in sequence: block sign-in → revoke sessions → remove licenses → optionally wipe Intune-enrolled devices. Each step is logged as a ticket note.

Password Reset

Helix → Vendor

Reset a client user password directly from a Helix ticket without opening the Microsoft Admin Center

ProtocolREST API call via Microsoft Graph
TriggerTech clicks Reset Password on a ticket or from client record → Microsoft 365 tab → [User] → Reset Password
AuthGDAP (preferred) or service account credentials
You configureNo additional configuration beyond provisioning setup.
Helix doesHelix resets the password and optionally flags the account to require a password change at next sign-in. The reset is logged as a ticket note with timestamp and performing tech.
// Vendor → HelixVendor notifies Helix

MFA Gap Reporting

Vendor → Helix

Detect users without MFA enrolled and surface them as Coach alerts

ProtocolScheduled API Poll — event-driven Coach alerts
TriggerHelix polls the client tenant MFA status daily. Any user without an enrolled MFA method fires a Coach alert.
AuthGDAP (preferred) or service account credentials
You configureNo configuration needed in the client tenant.
Helix doesCoach alerts appear on the client record and in the morning brief. Alerts dismiss automatically when MFA is enrolled. Persistent gaps can be escalated to a ticket.

Security Alerts

Vendor → Helix

Microsoft Entra ID Protection and Defender for Business risk events routed to Helix tickets and Coach alerts

ProtocolScheduled API Poll — event-driven ticket creation
TriggerRisk events: sign-in from unfamiliar location, leaked credentials detected, impossible travel, Defender malware detection
AuthGDAP with Security Reader role (minimum)
You configureEnsure the GDAP relationship includes the Security Reader role in addition to User Administrator and License Administrator.
Helix doesHigh-severity Entra risk events create Helix tickets automatically. Medium events fire Coach alerts. All events are logged on the client record security timeline.
// BidirectionalBoth sides communicate

License Management

Bidirectional

View, assign, and remove Microsoft 365 license assignments. Audit license overages and unused seats.

ProtocolREST API (both directions)
TriggerLicense tab in client record loads current assignments. Overages and unused seats surface automatically.
AuthGDAP (preferred) or service account credentials
You configureNo additional configuration beyond provisioning setup.
Helix doesHelix reads the client tenant license inventory and compares against contracted seats. Overages and approaching renewals fire as Coach alerts automatically.

Ready to connect?

Log into Helix and open App Marketplace to configure this integration.

Open Helix