Team: Huntress Managed Identity Threat Detection and Response (ITDR)
Environment: Microsoft 365
Summary: Use this guide to troubleshoot a Microsoft 365 ITDR integration that remains in an onboarding status. Find the status shown for the tenant in Huntress and jump to the matching section below.
In this Article
Before You Begin
Set Up
Data Sync
Subscriptions
Validation
Healthy
Unhealthy
Troubleshooting Tips
Frequently Asked Questions
Escalate to Huntress Support
Before You Begin
In Huntress, go to Integrations and open the Microsoft 365 identity integration.
Find the tenant, then select View Details next to Setup Status to see the current onboarding status and any available details. See Identity Provider Integration for more information about the integration page and status labels.
Allow time for Microsoft 365 processing. Microsoft 365 data can take 24–48 hours to fully sync with the Huntress Platform. If you recently enabled audit logging, allow up to 24 hours for that change to propagate before retrying the integration.
Do not repeatedly reauthorize or remove and re-add a tenant just because a status has not changed yet. First, follow the checks for the status shown below. Reauthorizing before correcting the underlying issue can cause the same delay to recur.
If your tenant uses a legacy integration view or does not show these statuses, do not unmap and re-add it just to match this guide. Contact Huntress Support for guidance; changing legacy mappings can cause temporary service downtime or data loss.
Set Up
What this status means: Huntress is verifying permissions and retrieving tenant information.
Try these checks:
Confirm you selected the correct Huntress organization and the intended Microsoft 365 tenant.
Confirm the Microsoft account used for sign-in is active and has the Global Administrator role required for this integration. Sign in with that account and complete the consent prompt, including accepting the requested permissions.
Confirm the tenant has an active Exchange license. Review the prerequisites in Setup the Microsoft 365 Integration for Huntress Managed ITDR if the setup or permissions step reports an error.
Retry signing in in a private or incognito browser window, with extensions disabled. This can help rule out browser cache or extension interference.
If the tenant is GCC High, confirm that the GCC High option was selected during setup. See Integrating with Huntress Managed ITDR for GCC High.
If the status remains at Set Up beyond the documented 24–48-hour sync window, or if the page displays an authentication or permission error, capture the full error text and continue to Escalate to Huntress Support. Avoid repeated sign-in attempts without correcting the reported issue.
Data Sync
What this status means: Huntress is synchronizing users and directory data from Microsoft 365.
Try these checks:
If onboarding has been running for less than 24–48 hours and no specific error is shown, allow the sync to continue. Microsoft 365 data may take this long to fully appear in Huntress.
Select View Details and note whether the status changes or an error appears. Record the time you checked and the exact status text.
Confirm the correct Microsoft 365 tenant was mapped to the intended Huntress organization. If the wrong tenant was selected, contact Support before unmapping or remapping it.
If the status remains unchanged after 48 hours, or the expected directory data is still missing after that period, contact Huntress Support with the tenant details and the current status.
Do not use Reauthorize simply to speed up a normal data sync. If the dashboard shows an authorization or permissions error, resolve that issue first and follow the guidance under Unhealthy.
Subscriptions
What this status means: Huntress is configuring Microsoft Graph change-notification subscriptions and audit-log webhooks. This status may appear as Subscriptions In Progress. These subscriptions enable Huntress ITDR to receive Microsoft 365 audit log data.
If onboarding remains at this status, verify the prerequisites before reauthorizing:
Check audit logging in Microsoft Purview. Sign in to the Microsoft Purview portal as an administrator, then go to Solutions > Audit. Confirm audit logging is enabled. If it is disabled, enable it and allow up to 24 hours for the change to propagate. See Microsoft 365 Audit Logging and Microsoft’s guidance for turning auditing on or off.
Confirm the tenant has a supported license. The existing troubleshooting guidance identifies Business Premium, E3, E5, or an equivalent plan as supporting unified audit logging. Confirm the tenant’s licensing with its Microsoft 365 administrator.
Verify the consented account. In the Microsoft Entra admin center, confirm the account used to authorize Huntress is active and still has the required role. If its role was removed or reduced, restore the required access before continuing.
Review access policies. Check whether Conditional Access, MFA step-up, device compliance, or application restrictions are preventing the integration from completing Microsoft Graph calls. Work with the tenant administrator to correct any policy that blocks the integration.
Reauthorize only after correcting any issue(s) above. In Huntress, open the tenant’s options menu and select Reauthorize, then complete consent with the required administrator account. See Reauthorize Huntress Managed ITDR Integration for the current steps.
The existing troubleshooting guidance notes that a Subscriptions failure may not display an error and may not retry automatically. The tenant is not monitored for ITDR audit-log data until this step completes. If the status returns to Subscriptions after you have verified the prerequisites and reauthorized, contact Huntress Support.
Validation
What this status means: Huntress is verifying event ingestion and completing setup.
Try these checks:
Allow the Microsoft 365 processing window to complete. Data can take 24–48 hours to fully sync, and recently enabled audit logging can take up to 24 hours to propagate.
Select View Details and review any status details or error text. If a specific error appears, follow its instructions rather than restarting onboarding.
Confirm audit logging remains enabled in Microsoft Purview and that the tenant’s authorization and permissions have not changed.
If Validation remains unchanged for more than 48 hours or the dashboard reports an error, collect the information listed under Escalate to Huntress Support.
Do not repeatedly reauthorize while Validation is still processing unless the dashboard identifies an authorization problem or Huntress Support recommends it.
Healthy
What this status means: The integration was added successfully.
No onboarding action is needed. Microsoft 365 data may still take up to 24–48 hours to fully sync. If the integration is Healthy but expected data is still missing after 48 hours, confirm that audit logging is enabled and contact Huntress Support with the tenant name, the time onboarding was completed, and the missing data.
Unhealthy
What this status means: The integration process failed. The dashboard may show error details and troubleshooting steps.
Select View Details and record the full error message or code.
Follow the error-specific instructions. Common checks include confirming that the consenting account still has the required access, that the tenant has a supported license, that audit logging is enabled, and that no Conditional Access or other access policy is blocking the integration.
If the details indicate an authorization issue or an outdated integration, correct the underlying cause, then use Reauthorize from the tenant’s options menu. See Reauthorize Huntress Managed ITDR Integration.
If the tenant remains Unhealthy after the cause is corrected and reauthorization is complete, contact Huntress Support. Do not repeatedly reauthorize without a new corrective action.
Troubleshooting Tips
1. Check audit logging status in Microsoft Purview
- Sign in to the Microsoft Purview compliance portal as a Global Administrator.
- Navigate to Solutions → Audit in the left navigation.
- Confirm that audit logging is enabled for the tenant.
- If auditing isn't enabled in your organization, a banner prompts you to start recording user and admin activity.
- Allow up to 24 hours for the change to propagate before proceeding.
2. Verify the consented account's role and status
- Sign in to the Microsoft Entra admin center (formerly Azure AD).
- Navigate to Users and locate the account used to authorize the Huntress ITDR integration.
- Confirm the account is active and not disabled or unlicensed.
- Navigate to Roles and administrators and confirm the account still holds the Global Administrator role or the required delegated role with audit log read permissions.
- If the role was removed or reduced, restore it before continuing.
--
--
3. Review conditional access policies
- In the Microsoft Entra admin center, navigate to Entra ID > Conditional Access > Policies.
- Review any active policies that apply to the consented admin account or to all users.
- Look for policies that enforce MFA step-up, device compliance, or app-based restrictions that could block the Huntress application from completing Graph API calls.
- If a policy is blocking access, work with the tenant's Microsoft 365 administrator to create an exclusion for the Huntress application or the consented admin account.
--
--
4. Confirm the tenant's license supports unified audit logging
- In the Microsoft 365 admin center, navigate to Billing > Licenses.
- Confirm the tenant holds an active Business Premium, E3, E5, or equivalent license.
- If the tenant has a license tier that doesn't include unified audit logging, the integration can't complete Step 3. Upgrade the license or contact the tenant's Microsoft account team before proceeding.
5. Reauthorize the Integration
Proceed with reauthorization only after completing all steps above. Reauthorization re-initiates the full onboarding flow, including Step 3. It does not delete existing detections or historical data for the tenant.
In the Huntress Dashboard, navigate to Integrations > Microsoft 365 > Edit Integration.
Locate the stalled tenant in the list.
Select "Reauthorize Microsoft" for that tenant.
Sign in with the Global Administrator account when prompted and complete the consent flow.
Monitor the integration status for up to one hour after reauthorization.
--
--
6. Verify it worked
After reauthorization, confirm that the integration completed successfully. It can take up to 24 hours to complete the setup process. However, most complete much sooner.
- In the Huntress Dashboard, navigate to Integrations > Microsoft 365 > Edit Integration.
- Locate the tenant you reauthorized.
- Confirm the integration status shows as Active or Connected, with no pending or incomplete indicators.
- Confirm that Step 3 no longer appears as "in progress" or "stuck".
If the status returns to active, the tenant will be monitored again, and Huntress ITDR will begin receiving audit log data. Allow up to one hour for the first detections to appear if audit logging was recently enabled.
If the integration remains stuck at Step 3 after reauthorization, move to the escalation step below.
Frequently Asked Questions
Why is my ITDR Microsoft 365 integration stuck at Step 3 for days with no error message?
Step 3 registers audit log webhooks with Microsoft Graph. If it fails, the Huntress portal shows no error and does not retry automatically. The most common cause is that Microsoft 365 audit logging is disabled on the tenant. Check the Purview compliance portal to enable it, then reauthorize the integration in Huntress after confirming all prerequisites are met.
Will reauthorizing the ITDR integration fix a Step 3 stall?
Only if the underlying Microsoft issue is resolved first. Reauthorizing without enabling audit logging or fixing permission issues will cause the same stall to repeat. Always verify Microsoft prerequisites before using the Reauthorize option.
Is the Microsoft 365 tenant being monitored while the ITDR integration is stuck at Step 3?
No. Until onboarding completes successfully, Huntress ITDR does not receive audit log data for that tenant and can't generate detections. Promptly resolving the Step 3 stall is important to avoid coverage gaps.
Does every Microsoft 365 license support ITDR audit logging?
No. Unified audit logging requires Business Premium, E3, E5, or an equivalent license. Some other tiers do not include this feature. Confirm the tenant has a supported license before troubleshooting further.
Can a previously working integration get stuck at Step 3 during reauthorization?
Yes. If conditional access policies, MFA requirements, or admin account roles change after the initial setup, a reauthorization attempt can stall at Step 3, just as it would during new onboarding. Review all prerequisites in the "Before you begin" section, even if the integration was working previously.
How long should I wait after enabling audit logging before reauthorizing?
Allow up to 24 hours for audit logging to fully propagate across the tenant before attempting reauthorization. Reauthorizing too soon may result in another stall.
Escalate to Huntress Support
If the integration remains stuck after reauthorization and all Microsoft prerequisites are confirmed, gather the following before opening a ticket:
- The affected tenant name and domain
- The Microsoft 365 admin account used for consent
- The date the integration was configured or reauthorized
- Whether this is a new onboard or a previously working integration that stopped after a potential change
After the information is gathered, select the "Submit a request" button located below.