Microsoft-first transparency

Integration status, permissions and current limits.

Microsoft provides powerful identity, security, data and agent controls. Orbit correlates relevant signals across those platforms around one operating question: what delegated authority exists, how is it controlled and what evidence can the organization defend?

Current verified repository state: this public website contains the assessment intake flow and content registry. It does not contain a Microsoft connector, app registration, Graph client, token store or tenant scan engine. No Microsoft integration is presented as available or beta based on this repository alone.

Integration matrix

What each Microsoft source means for Orbit.

Microsoft Entra ID

entra

Statusvalidation
Orbit use

Planned first assessment source for tenant identity context, owners, enterprise applications, app roles and service principals.

  • Tenant identity metadata under review
  • Enterprise applications under review
  • Service principals under review
  • App registrations under review
Licensing dependencies and limitations

Licensing

  • Tenant and Entra capabilities must be reviewed before connection.

Limitations

  • No Entra connector exists in this website repository.
  • Exact Graph permissions and least-privilege alternatives are not finalized.
  • No tenant scan has been verified from this repository.

Microsoft Graph

graph

Statusvalidation
Orbit use

Candidate API layer for directory, permission and ownership metadata during a read-only assessment.

  • Directory metadata under review
  • Permission metadata under review
  • Activity metadata not yet verified
Licensing dependencies and limitations

Licensing

  • API availability and tenant licensing must be verified per customer scope.

Limitations

  • No Graph client, OAuth flow or endpoint usage is implemented in this website repository.
  • No activity coverage guarantee is made.

Copilot Studio

copilot-studio

Statusplanned
Orbit use

Planned validation source for agent, topic, action and environment discovery.

  • Agent metadata planned
  • Action metadata planned
  • Environment context planned
Licensing dependencies and limitations

Licensing

  • Customer licensing and API availability must be validated.

Limitations

  • No Copilot Studio connector exists in this repository.

Power Platform, Power Automate and Power Apps

power-platform

Statusplanned
Orbit use

Planned validation source for environments, connectors, flows, apps and solution context.

  • Environment metadata planned
  • Connector metadata planned
  • Flow and app context planned
Licensing dependencies and limitations

Licensing

  • Power Platform licensing and admin API access must be validated.

Limitations

  • No Power Platform connector exists in this repository.

Microsoft Purview

purview

Statusplanned
Orbit use

Planned source for sensitivity, policy and data governance context where licensed.

  • Sensitivity and policy context planned
Licensing dependencies and limitations

Licensing

  • Purview licensing and data availability must be confirmed per tenant.

Limitations

  • No Purview connector or classification import exists in this repository.

Microsoft Defender

defender

Statusplanned
Orbit use

Planned source for security findings and exposure context.

  • Alert and exposure context planned
Licensing dependencies and limitations

Licensing

  • Defender licensing and API access must be validated.

Limitations

  • No Defender connector exists in this repository.

Microsoft Teams and SharePoint Online

sharepoint

Statusplanned
Orbit use

Planned source for collaboration and data-reach context after permission review.

  • Teams metadata planned
  • SharePoint site and file metadata planned
Licensing dependencies and limitations

Licensing

  • Microsoft 365 licensing, API limits and consent scope must be reviewed.

Limitations

  • No Teams or SharePoint connector exists in this repository.
  • Content access is not approved; metadata-only alternatives must be assessed first.

Azure AI and Azure OpenAI

azure

Statusvision
Orbit use

Future direction for AI resource and model deployment context beyond the first Microsoft 365-focused assessment.

  • Azure resource metadata not yet scoped
Licensing dependencies and limitations

Licensing

  • Azure subscription access model not yet documented.

Limitations

  • No Azure Resource Manager, Azure AI or Azure OpenAI connector exists in this repository.

Logic Apps and Managed Identities

azure

Statusvision
Orbit use

Future source for automation identity and workflow authority context.

  • Logic Apps metadata not yet scoped
  • Managed identity metadata not yet scoped
Licensing dependencies and limitations

Licensing

  • Azure access model not yet documented.

Limitations

  • No Logic Apps or managed identity discovery exists in this repository.

Permissions

Current Microsoft permission register.

No production Microsoft permission configured in this repository

Microsoft Identity Platform / Microsoft Graph

validation
Type
application
Access
read
Admin consent
Required

Purpose

Documents the current verified state: the public website repository has no Microsoft app registration, Graph scopes, Azure resource permissions or token storage implementation.

Effect if denied

No Microsoft tenant discovery runs from this website repository. Assessment requests can still be submitted through the website form.

Objects accessed

  • None in this repository

Fields stored and retention

None in this repository

Not applicable until Microsoft discovery is implemented and approved.

Least privilege

Current least-privilege finding.

No Microsoft permission is currently configured in this website repository, so there is no active Microsoft write permission to remove. The public read-only claim is therefore limited to the intended assessment principle, not an implemented connector guarantee.

Before any Microsoft tenant connection, the exact application or delegated permissions must be added to the registry with purpose, accessed objects, stored fields, alternatives, denial impact and founder/security review.

Review authentication and trust model