Quick Start Guide
Get your M365 automation up and running in under 30 minutes. This guide covers everything from app registration to your first tenant deployment.
Overview
Five steps to a fully operational multi-tenant M365 automation platform. Total estimated time: ~30 minutes. CONFIG365 runs as a single all-in-one container — no Azure DevOps organization required.
Prerequisites
- A container host — Azure Container Apps, Azure App Service (Web App for Containers), or any Docker host
- Global Administrator access to your MSP tenant
- Microsoft 365 tenant(s) to manage
- A domain name or IP address for the CONFIG365 portal (port 80)
Create Multi-Tenant App — 5 min
Register the App
- Go to Azure Portal → Microsoft Entra ID → App registrations → New registration
- Set Name to
M365-Automation - Set Supported account types to Accounts in any organizational directory (Multitenant)
- Click Register and save the Application (Client) ID
Create Client Secret
- Go to Certificates & secrets → New client secret
- Set expiry to 24 months, click Add
- Save the secret value immediately — it cannot be retrieved later.
Allow public client flows
- Go to Authentication → Advanced settings
- Set Allow public client flows to Yes and save
- Required for the OAuth2 device code flow used when connecting a tenant in the portal.
Add Microsoft Graph Permissions (Delegated)
Go to API permissions → Add a permission → Microsoft Graph → Delegated permissions. Do not add Application permissions — CONFIG365 uses delegated auth (device code + refresh token) on behalf of the signed-in admin.
| Permission |
|---|
Application.ReadWrite.All |
AuditLog.Read.All |
CustomSecAttributeDefinition.ReadWrite.All |
DeviceManagementApps.ReadWrite.All |
DeviceManagementConfiguration.ReadWrite.All |
DeviceManagementManagedDevices.ReadWrite.All |
DeviceManagementManagedDevices.PrivilegedOperations.All |
DeviceManagementScripts.ReadWrite.All |
DeviceManagementServiceConfig.ReadWrite.All |
Directory.AccessAsUser.All |
Directory.ReadWrite.All |
Group.ReadWrite.All |
MailboxSettings.ReadWrite |
offline_access |
Policy.Read.All |
Policy.ReadWrite.AuthenticationMethod |
Policy.ReadWrite.Authorization |
Policy.ReadWrite.ConditionalAccess |
Policy.ReadWrite.DeviceConfiguration |
Policy.ReadWrite.MobilityManagement |
Policy.ReadWrite.PermissionGrant |
RoleManagement.ReadWrite.Directory |
SecurityEvents.Read.All |
User.Read.All |
Add Exchange Online Permissions (Delegated)
Go to Add a permission → APIs my organization uses → search "Office 365 Exchange Online" and select Delegated permissions.
| Permission |
|---|
Exchange.Manage |
Add SharePoint Online Permissions (Delegated)
Go to Add a permission → SharePoint → Delegated permissions (or APIs my organization uses → "Office 365 SharePoint Online").
| Permission |
|---|
AllSites.FullControl |
Add Microsoft Defender for Endpoint Permissions (optional)
Required only if you use the Defender Device Backup feature (app protection / device inventory). Go to Add a permission → APIs my organization uses → search "WindowsDefenderATP" and select Delegated permissions.
| Permission |
|---|
Machine.Read |
https://api.securitycenter.microsoft.com/.default).
The signed-in admin also needs an MDE role (Security Operator or higher).
The same Graph access app in MSP settings is reused — no separate app registration is needed.
Grant Admin Consent
- Click Grant admin consent for [Your Organization] and confirm
- All permissions should show a green checkmark
Deploy the CONFIG365 Container — 5 min
Before you start: the CONFIG365 image is distributed privately to licensed customers. Email [email protected] and we will issue your registry credentials and image reference.
Run the container
No .env file is required. Session secrets, Gitea admin credentials, and pipeline keys are generated on first boot and persisted on the data volume. Open http://localhost:8080/setup for the wizard.
docker login <your-config365-registry> docker run -d --name config365-aio --restart unless-stopped \ -p 8080:80 \ -v config365-data:/home/config365-data \ <your-config365-registry>/config365:latest
Host port 8080 maps to Caddy on port 80 inside the container (portal, Gitea at /gitea/, runner, and token-api).
Optional: Docker Compose plus a .env is only needed to change the host port (PORTAL_HTTP_PORT) or other settings. Leave SESSION_SECRET blank if you use that file.
Tip: After the setup wizard, CONFIG365 creates the Gitea config365 platform org, seeds workflow templates, and registers the act_runner. No manual Gitea setup is needed.
Onboard First Tenant — 10 min
Get Tenant Consent
Generate a consent URL and send it to the tenant's Global Administrator:
https://login.microsoftonline.com/organizations/adminconsent?client_id=YOUR-APP-CLIENT-ID After they accept, collect their Tenant ID from the Entra admin center Overview page.
Add the tenant in the CONFIG365 portal
- 1. Open the CONFIG365 portal at
http://your-hostand log in - 2. Navigate to Tenants → + Onboard
- 3. Enter the tenant domain, Tenant ID, and your MSP app Client ID
- 4. Click Save — the portal bootstraps a
tenant-contosoGitea repo with workflow files automatically
Note: The portal stores the tenant's credentials encrypted in SQLite. You never need to touch Gitea directly — the portal manages secrets as Gitea org-level variables scoped to the MSP org.
Deploy — 5 min
Trigger a deploy from the portal
- From the Tenant Dashboard, click Deploy on the tenant card
- The Gitea Actions deploy-pipeline.yml workflow starts automatically
- The WhatIf stage runs first — review what will be created or updated
- The pipeline pauses at the Apply stage awaiting approval
Review and Approve
- In the CONFIG365 portal, open the WhatIf diff for the pending run
- Review every create / update / delete across all policy types
- Click ✓ Approve — the Apply stage triggers immediately in Gitea Actions
- Monitor the run output for per-resource status
Backups — Automatic
Daily at 2 AM UTC
backups/ in the tenant Gitea repo
All M365 configurations
Manual backup
- 1. From the CONFIG365 portal dashboard, click Backup on the tenant card
- 2. The backup Gitea Actions workflow triggers immediately — no additional configuration needed
Next Steps
Troubleshooting
"Authentication failed"
- – Verify the app Client ID and Client Secret in the CONFIG365 portal tenant settings
- – Check that the correct Tenant ID is saved for this tenant
- – Ensure the tenant granted admin consent for your multi-tenant app
"Tenant not found"
- – Double-check the Tenant ID in the CONFIG365 portal tenant settings
- – Verify the tenant ID contains no typos
"Group not found in target tenant"
- – Referenced group does not exist yet
- – Ensure groups are deployed before policies that reference them
- – Check group display name matches exactly (case-sensitive)
"Insufficient privileges"
- – Review app permissions in Entra ID
- – Ensure all required delegated Graph / Exchange / SharePoint permissions are assigned (not Application permissions)
- – Verify admin consent was granted