> For the complete documentation index, see [llms.txt](https://docs.rewst.help/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.rewst.help/rewst-documentation/documentation/integrations/integration-guides/microsoft-cloud-integration-bundle.md).

# Microsoft Cloud Integration Bundle

{% hint style="info" %}
Were you a Rewst Classic customer? Microsoft integration is now easier in Rewst. The in-platform setup wizard will walk you through all the needed steps for integration.
{% endhint %}

## What is the Microsoft Cloud Integration Bundle?

Rewst can't work with Microsoft 365 and its related apps until you've given it permission to. Setting up the Microsoft integration is how you give that permission: first for your own company, then for each customer you manage.

<figure><img src="https://3039672601-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fh0G0em3PH6aDfPoI5XpN%2Fuploads%2FcKAPsuXALDGwXlROJlyj%2FScreenshot%202026-09-24%20at%209.50.17%E2%80%AFAM.png?alt=media&amp;token=71df3608-4b21-4793-b769-f0bca3f88aed" alt=""><figcaption><p>Find the <strong>Set up</strong> button to start integration for Microsoft at the top of your Integrations page.</p></figcaption></figure>

When setup is finished, Rewst can do Microsoft 365 admin work for you and your customers automatically. For example:

* Create a new user: make the account, assign licenses, add them to groups
* Remove a user: block sign-in, remove licenses, hand the mailbox to someone else
* Reports: list users, licenses, MFA status, and security settings for every customer
* Mail tasks: shared mailboxes, forwarding, distribution lists - these use Exchange Online, which is part of the same setup

{% hint style="info" %}
Though you’ll be working from one integration menu tile to set up all integrations, each integration will appear as its own section with its own actions in the actions list of the workflow builder.
{% endhint %}

## How does the Microsoft integration work?

Rewst gets its access to your customers through Microsoft's partner program:

* Cloud Solution Provider (CSP): Microsoft's program for IT providers who resell and manage Microsoft 365 for customers. Your Partner Center account is where this is managed.
* Granular Delegated Admin Privileges (GDAP): a permission agreement between you and each customer. It sets exactly which admin rights you hold in that customer's Microsoft 365, and for how long. The customer has to approve it.

The chain looks like this:

<figure><img src="https://3039672601-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fh0G0em3PH6aDfPoI5XpN%2Fuploads%2FJklGxizLzSgigLAQkZL8%2FScreenshot%202026-09-24%20at%209.43.34%E2%80%AFAM.png?alt=media&amp;token=5f5d791c-020a-44b3-b3ce-11a91928e6d4" alt=""><figcaption></figcaption></figure>

Rewst never stores a separate password for each customer. It works through your company's partner connection, and it can only do what each customer's GDAP permissions allow.

## **What integrations are in the Microsoft Cloud Integration Bundle?**

The Microsoft Cloud Integration Bundle contains integrations for:

1. **Microsoft Graph:** A unified API that provides a single endpoint for accessing and managing data and intelligence across Microsoft 365, Windows, and Enterprise Mobility and Security.<br>
2. **Microsoft Exchange Online:** The cloud-hosted version of the traditional Microsoft Exchange Server, offering similar functionalities but without the need for on-premises server infrastructure.<br>
3. **Microsoft Cloud Solution Provider (CSP)**: This allows for the resale of Microsoft cloud services like Azure, Microsoft 365, and Dynamics 365 to businesses, often with added value services. It's a subscription-based model where MSPs can bill customers.<br>
4. **Microsoft Azure**: A cloud computing platform, Azure offers a range of cloud infrastructure services, including computing, analytics, storage, networking, and AI. Note that Microsoft formerly called a different tool Azure, and renamed that tool Microsoft Entra.<br>

## Set up the Microsoft Cloud Integration Bundle

{% hint style="info" %}
Follow our in-platform wizard to set up the Microsoft Cloud Integration Bundle. Below is a high-level overview of what will happen during all the steps. While the Rewst Agent can help you with questions and setup, much of the credentialing and information entered as part of the setup process must be done by you.
{% endhint %}

<figure><img src="https://3039672601-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fh0G0em3PH6aDfPoI5XpN%2Fuploads%2FTnREhVj7cCXZ29pOGMGz%2FScreenshot%202026-09-24%20at%209.54.01%E2%80%AFAM.png?alt=media&amp;token=bdd1c61c-ff31-46a6-b524-cd13ab5eaa48" alt=""><figcaption></figcaption></figure>

#### High-level overview of setup

1\. Connect Rewst to your own company's Microsoft account

* Someone with Global Admin rights in your company's Microsoft 365, who also has access to Partner Center, signs in through Rewst's setup screen.
* They approve and consent to the Rewst app. This adds Rewst as a trusted app in your company's Microsoft account.
* Result: Rewst is linked to your company.

2\. Make sure each customer has an active GDAP relationship

* Each customer needs a GDAP relationship with you, and the customer must accept it.
* Many IT providers already have these in place. If a customer doesn't, you request one in Partner Center (or through Rewst's tools) and the customer approves it.
* Result: you have a legal, time-limited admin connection to each customer.

3\. Choose a permission level

* Rewst offers ready-made permission tiers, roughly from least to most access: Auditor for read-only, Helpdesk, Infrastructure, Automation, Global Admin, and Custom.
* You pick a default tier for all customers, and you can change it for individual customers.
* A good rule: give Rewst only the level your automations actually need.
* Result: Rewst knows how much it may do in each customer's account.

4\. Apply those permissions to each customer

* Rewst pushes your chosen permissions to each customer's account.
* Result: Rewst's app is allowed inside each customer's Microsoft 365, at the level you chose.

5\. Match Microsoft customers to Rewst customers

* Rewst pulls your customer list from Microsoft. Each Microsoft customer gets linked to the matching customer in Rewst.
* Result: when an automation runs "for Customer A," Rewst knows which Microsoft account to act on.

6\. Test with something harmless

* Run a read-only task against one customer first, like listing their users.
* Result: you've confirmed the whole chain works before running anything that makes changes.

{% hint style="info" %}
If you aren't a Microsoft partner (CSP)**,** or you only want to manage one Microsoft account— for example, your own company's— , setup is simpler. You connect that one account directly and skip the GDAP steps.
{% endhint %}

#### What you'll need before you start

| Item                                         | Why                                                                 |
| -------------------------------------------- | ------------------------------------------------------------------- |
| A Microsoft Global Admin in your own company | To approve the Rewst app in step 1                                  |
| Access to Partner Center (CSP)               | Customer relationships and GDAP are managed there                   |
| Customers willing to approve GDAP requests   | Only needed for customers who don't already have one                |
| Admin rights in Rewst                        | To run the Microsoft setup inside Rewst                             |
| A decision on permission level               | "Read-only reports" and "full user management" need different tiers |

#### What is GDAP and why is it important to the setup process?

In 2024, Microsoft moved away from regular user-based access, where users logged into Microsoft Entra with an individually permissioned account. Instead, they now operate via delegated admin permissions, where permissions are assigned from the top level down, for more secure access management. This is known as *Granulated Delegated Admin Permissions*, or *GDAP*.

## Troubleshoot the Microsoft Cloud integration bundle setup

Frequent errors stem from a customer's GDAP relationship that has expired or was never approved, or if the permission tier is set too low for the task. The automation then fails with a "permission denied" error for that one customer. Fixing that customer's GDAP or tier fixes it.

Your first step for any troubleshooting should be to ask the Rewst Agent to assess your situation and provide advice. For additional assistance, we have a separate guide with all bundle troubleshooting information. View that page [here](/rewst-documentation/documentation/integrations/integration-guides/microsoft-cloud-integration-bundle/microsoft-cloud-integration-bundle-troubleshooting-guide.md).&#x20;


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.rewst.help/rewst-documentation/documentation/integrations/integration-guides/microsoft-cloud-integration-bundle.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
