AI security & operations for MSPs

Microsoft 365

Microsoft 365

Hal reads your clients’ Microsoft 365 audit activity through the Microsoft 365 Management Activity API, over read-only credentials you grant and can revoke at any time. He writes to the tenant only to turn on its audit-log subscription, which Microsoft needs on before it serves the log, and, when he builds the app registration himself, to create it and later repair, reset or rotate it, each under your admin’s own sign-in.

What’s collected:

  • The unified audit log across workloads, Exchange, SharePoint, OneDrive, Teams
  • Mailbox operations, file and sharing activity, and admin actions
  • The result and the acting account for each event

Events are polled every few minutes and retained for 365 days, searchable across every connected tenant.

Note

Prerequisite: the tenant must have Unified Audit Logging enabled before Hal can read it. See Audit Logging Prerequisites.

Connect it: in the portal chat, either way Getting Started describes: Hal creates the read-only registration with Hal-assisted onboarding, or you build it as the manual page describes and paste its credential on Settings → Microsoft 365.

Sign-in and identity activity comes from Entra ID, a separate feed.

See what Hal surfaces on your own clients.

No deck. Ask us anything first. When you want to see Hal on your own tenants, we sign a short evaluation agreement and stand up your instance; you connect one tenant, Hal watches it for 14 days, and we walk you through what he found.

  1. 01You ask us your questions. No deck, no demo dataset.
  2. 02You sign a short evaluation agreement, and we stand up your own instance.
  3. 03You connect one tenant from your own admin console. Hal watches it for 14 days.
  4. 04We walk through what he found. Keep going month to month, or revoke the scopes yourself and stop.