Set Up Instructions

Microsoft

There are two ways to connect Ploy to Microsoft. This guide covers the quick default. If you prefer to create your own app registration and control permissions directly, see Connect Microsoft with your own app registration.

Mode

Best for

Ploy managed app (this guide)

Quick setup with a single admin consent.

Your own app registration

Full control over the access you grant Ploy. You create the app and manage the federation yourself.

Ploy managed app is the fastest path. Your own app registration is best if you want full control over the exact permissions Ploy receives.


Follow the steps below to integrate your Microsoft account with Ploy in seconds.

  1. Navigate to Ploy's integration page in your Ploy account: https://app.joinploy.com/integrations

  2. Click "Add" on the Microsoft integration widget

  3. Enter your Microsoft Tenant domain. This is your primary domain located here.

  4. Decide whether you want Ploy to scan for receipts as part of the detection engine, this can help identify Shadow Spend if personal cards can be used within the business as well as help retrieve invoices automatically

    1. Select "Yes" to scan for receipts (recommended)

    2. Select "No" to disable this

  5. Click Authenticate and follow the Microsoft authentication, be sure to authenticate with your admin account, this doesn't have the be the same as the account you signed up / logged in to Ploy with

  6. Name the connection something useful e.g. Ploy Microsoft Integration

  7. Click Test

  8. Click Save

Include apps without a website as resources?

During setup, Ploy asks whether apps without a website should be included as resources. Your Microsoft tenant may contain many of these — internal machine-to-machine apps such as Power Platform connectors, Dataverse plugins, and automation service principals.

  • No (default): Only apps with a website (a homepage, sign-in or reply URL) become resources in Ploy. Apps without one are still scanned and tracked as non-human identities — they just don't appear in your resource inventory.

  • Yes: Every enterprise application becomes a resource, including internal machine-to-machine apps, so your resource inventory and access reviews cover all app access. In tenants with many internally-registered apps this can add thousands of resources.

You can change this at any time by editing the integration. After enabling it, the newly included apps appear as resources on the next full scan, within 24 hours. If an app is later deleted from your tenant, its resource is archived like any other.

Was this helpful?