Skip to content

SSO

Microsoft 365
API integration

Ship SSO features without building the integration. Full Microsoft 365 API access via Proxy, normalized data through Unified APIs, and 80+ MCP-ready tools for AI agents — all extensible to your exact use case.

Talk to us
Microsoft 365

Use Cases

Why integrate with Microsoft 365

Common scenarios for SaaS companies building Microsoft 365 integrations for their customers.

01

Sync your customer's corporate directory for identity-aware features

SaaS platforms offering role-based access, audit trails, or org-chart visualizations can pull Users, Roles, and Licenses from Microsoft Entra ID via the Unified User Directory API — giving their product accurate, up-to-date identity context without asking customers to manually upload CSVs.

02

Connect to SharePoint and OneDrive for document-centric workflows

Any SaaS product that touches customer documents — contract management, compliance, AI search — can read and write Drive-Items, manage Permissions, and browse Drives through the Unified File Storage API, so end users never have to leave your app to find their files.

03

Power real-time collaboration through Microsoft Teams messaging

SaaS companies building project management, incident response, or helpdesk tools can create Channels, post Messages, and manage Members inside their customers' Teams workspaces via the Unified Instant Messaging API, keeping stakeholders informed without context switching.

04

Surface SharePoint intranet content inside your product

Knowledge management and enterprise search platforms can ingest Pages, Spaces, and Page-Content from SharePoint sites through the Unified Knowledge Base API to power search indexes, RAG pipelines, or content dashboards that reflect the customer's internal knowledge base.

05

Automate IT ticketing workflows tied to Microsoft 365 accounts

Helpdesk and ITSM SaaS products can create and manage Tickets, track priorities, and resolve issues using the Unified Ticketing API while correlating tickets to Microsoft 365 user identities — enabling automated routing, SLA tracking, and self-service IT support inside Teams.

What You Can Build

Ship these features with Truto + Microsoft 365

Concrete product features your team can ship faster by leveraging Truto’s Microsoft 365 integration instead of building from scratch.

01

Automated user provisioning from Entra ID

Read Users, Roles, and Licenses from Microsoft Entra ID via the Unified User Directory API to automatically provision and deprovision accounts in your product when customers' directories change.

02

One-click OneDrive and SharePoint file picker

Let end users browse Drives and attach Drive-Items from their OneDrive or SharePoint document libraries directly into your app's workflows using the Unified File Storage API.

03

Teams channel notifications for key events

Post rich Messages to a customer's Microsoft Teams Channels via the Unified Instant Messaging API whenever important events happen in your product — ticket updates, deal closures, deployment alerts.

04

Permission-aware enterprise search index

Ingest Drive-Items and their Permissions alongside Knowledge Base Pages and Spaces to build a search experience that respects each user's Microsoft 365 access controls.

05

Cross-platform ticket sync with Microsoft 365 context

Create and update Tickets via the Unified Ticketing API while enriching them with user profile data from the Unified User Directory API for smarter routing and prioritization.

06

SSO-powered app user mapping

Use the Unified Single Sign-On API to map App Users and Apps to your product's internal accounts, streamlining onboarding for organizations that authenticate everything through Microsoft.

SuperAI

Microsoft 365 AI agent tools

Comprehensive AI agent toolset with fine-grained control. Integrates with MCP clients like Cursor and Claude, or frameworks like LangChain.

list_all_microsoft_365_teams

List Microsoft teams in the organization, with optional OData ordering, property selection, and entity expansion. Returns each team object including its id, displayName, description, memberSettings, and createdDateTime. Results are paginated.

get_single_microsoft_365_team_by_id

Get the properties and relationships of a specific Microsoft team by id. Returns the team object, identified by its id. Required: id.

list_all_microsoft_365_team_members

List members of a Microsoft team. Returns each conversation member's id plus its subtype-specific fields (attributes); membership ids are opaque strings and members may span tenants. Required: team_id.

get_single_microsoft_365_team_member_by_id

Get a single conversation member of a Microsoft team by id. Returns: id, displayName, roles, visibleHistoryStartDateTime, attributes, token_type, expires_in, ext_expires_in, access_token. Required: team_id and id.

delete_a_microsoft_365_team_member_by_id

Remove a conversation member from a Microsoft team by id. Returns an empty 204 response on success. Required: team_id and id.

list_all_microsoft_365_search

Run a Microsoft Search query across Microsoft 365 content and return the matching search hits. Returns: id. Required: requests. Max 15 hits per page.

list_all_microsoft_365_users

List Microsoft Entra user objects in the directory. Returns: id, displayName, givenName, surname, userPrincipalName, mail, jobTitle, businessPhones, mobilePhone, officeLocation, preferredLanguage. Supports $search, $filter, $orderby, $select, and $expand; $search and $count queries require the ConsistencyLevel 'eventual' header.

get_single_microsoft_365_user_by_id

Get a Microsoft Entra user by id. Returns: id, birthday, city, country, department, identities, interests, mail, print, responsibilities, schools, skills, state, surname, activities, authentication, calendar, calendars, chats, contacts, drive, drives, events, extensions, insights, manager, messages, notes, onenote, outlook, people, photo, photos, planner, presence, settings, solutions, sponsors,…

delete_a_microsoft_365_user_by_id

Delete a Microsoft Entra user by id. Returns an empty 204 response on success. Deleted users, including their mailbox and license assignments, are moved to a temporary container and can be restored within 30 days; after 30 days the object is permanently deleted. Required: id.

list_all_microsoft_365_me

Get the profile of the signed-in user from Microsoft Graph via the /me endpoint. Returns: id, birthday, city, country, department, identities, interests, mail, print, responsibilities, schools, skills, state, surname, activities, authentication, calendar, calendars, chats, contacts, drive, drives, events, extensions, insights, manager, messages, notes, onenote, outlook, people, photo, photos,…

list_all_microsoft_365_channels

List channels of a Microsoft Teams team. Returns each channel's id, displayName, and membershipType. Requires team_id.

get_single_microsoft_365_channel_by_id

Get a single Microsoft Teams channel by id. Returns the channel object including id, displayName, and membershipType. Requires team_id and id.

create_a_microsoft_365_channel

Create a new channel in a Microsoft Teams team. Returns the created channel with its id, displayName, and membershipType. Requires team_id and displayName (max 50 characters; private channels allow up to 200 members).

update_a_microsoft_365_channel_by_id

Update a Microsoft Teams channel by id with a partial channel payload (e.g. displayName, membershipType). Returns an empty 204 response on success. Requires team_id and id.

delete_a_microsoft_365_channel_by_id

Delete a Microsoft Teams channel by id. Returns an empty 204 response on success. Requires team_id and id.

list_all_microsoft_365_chats

List the Microsoft Teams chats the signed-in user is part of. Returns: id, members, lastMessagePreview. Supports $orderby, $select, and $expand to shape results.

get_single_microsoft_365_chat_by_id

Get a single Microsoft Teams chat by id (without its messages). Returns: id, topic, viewpoint, members, messages, tabs. Required: id. Supports $select and $expand.

create_a_microsoft_365_chat

Create a new Microsoft Teams chat in Microsoft Graph. Returns the created chat object with its id plus the chat's properties (attributes) as defined by the Microsoft Graph chat resource schema.

update_a_microsoft_365_chat_by_id

Update the properties of a Microsoft Teams chat by id. Returns an empty 204 response on success. Required: id.

delete_a_microsoft_365_chat_by_id

Soft-delete a Microsoft Teams chat by id. Returns an empty 204 response on success. Required: id.

list_all_microsoft_365_chat_messages

List the messages in a Microsoft Teams chat. Returns chatMessage records including their id. Supports the OData options $select, $expand, $orderby, $filter, and $search. Required: chat_id.

get_single_microsoft_365_chat_message_by_id

Get a single message or message reply from a Microsoft Teams chat. Returns the chatMessage record, identified by its id. Required: chat_id and id.

create_a_microsoft_365_chat_message

Send a new message to a Microsoft Teams chat. Returns the created chatMessage record, identified by its id. Required: chat_id and a chatMessage request body. This API can't create a new chat; the chat must already exist.

update_a_microsoft_365_chat_message_by_id

Update a message in a Microsoft Teams chat by supplying the chatMessage property values to apply. Returns an empty 204 response on success. Required: chat_id, id, and a chatMessage request body.

delete_a_microsoft_365_chat_message_by_id

Soft delete a Microsoft Teams chat message in a chat owned by the signed-in user; the deletion can be undone via the undoSoftDelete action. Returns an empty 204 response on success. Required: chat_id, id.

list_all_microsoft_365_channel_messages

List messages (without replies) in a Microsoft Teams channel. Returns chatMessage records including id and policyViolation. Required: team_id, channel_id (team_id falls back to the connection's default workspace when omitted).

get_single_microsoft_365_channel_message_by_id

Get a single message in a Microsoft Teams channel by id. Returns the chatMessage record including id and policyViolation. Required: team_id, channel_id, id.

create_a_microsoft_365_channel_message

Send a new message to a Microsoft Teams channel. Returns the created chatMessage record including id and policyViolation. Required: team_id, channel_id, and a chatMessage request body.

update_a_microsoft_365_channel_message_by_id

Update a message in a Microsoft Teams channel by id, typically to set or clear its policyViolation (DLP) status. Returns an empty 204 response on success. Required: team_id, channel_id, id.

delete_a_microsoft_365_channel_message_by_id

Soft-delete a message in a Microsoft Teams channel by id, marking it as deleted without permanently removing it. Returns an empty 204 response on success. Required: team_id, channel_id, id.

list_all_microsoft_365_buckets

List the buckets (columns) of a Microsoft Planner plan. Returns bucket objects including id, name, planId, orderHint, and createdDateTime. Required: plan_id.

get_single_microsoft_365_bucket_by_id

Get a single Microsoft Planner bucket by id. Returns the bucket object including id, name, planId, orderHint, and createdDateTime. Required: id.

delete_a_microsoft_365_bucket_by_id

Delete a Microsoft Planner bucket by id. Returns an empty 204 response on success. Required: id.

update_a_microsoft_365_bucket_by_id

Update a Microsoft Planner bucket by id, such as renaming it or changing its orderHint. Returns the updated bucket object including id, name, planId, and orderHint. Required: id and etag_value (If-Match ETag for optimistic concurrency).

create_a_microsoft_365_bucket

Create a new Microsoft Planner bucket. Returns the created bucket object including id, name, planId, orderHint, and createdDateTime.

list_all_microsoft_365_attachments

List the external reference links attached to a Microsoft Planner task's details. Returns the references dictionary where each entry has alias, previewPriority, type, and url. Required: task_id.

microsoft_365_attachments_download

Download the raw file content in Microsoft from a direct download URL. Returns the file's binary content stream rather than a JSON object. Required: base, path.

get_single_microsoft_365_attachment_by_id

Get the shared driveItem behind a Microsoft sharing link. Returns the item's id, name, size, and webUrl. A sharing URL must be transformed into a sharing token before use. Required: id.

list_all_microsoft_365_tasks

List the Planner tasks in Microsoft that belong to a specific plan. Returns Planner task records, each identified by its id. Required: plan_id.

get_single_microsoft_365_task_by_id

Get a single Planner task in Microsoft by id, including its properties and relationships. Returns the planner task object; the source documents only its id — remaining fields follow the Microsoft Graph plannerTask schema. Optional $select and $expand can narrow or expand the returned properties. Required: id.

delete_a_microsoft_365_task_by_id

Delete a Planner task in Microsoft by id. Optionally pass etag_value to match the task's ETag for optimistic concurrency. Returns an empty 204 response on success. Required: id.

update_a_microsoft_365_task_by_id

Update a Planner task in Microsoft by id with a JSON body of planner task property values. Returns an empty 204 response on success. Required: id, etag_value (supplied as the If-Match ETag header, required by Microsoft Graph for this call).

list_all_microsoft_365_me_plans

List Microsoft Planner plans shared with the signed-in user. Returns: id, title, owner, createdBy, createdDateTime, context.

get_single_microsoft_365_me_plan_by_id

Get a single Microsoft Planner plan by id. Returns: id, container, createdBy, createdDateTime, owner, title, buckets, details, tasks, context, token_type, expires_in, ext_expires_in, access_token. Required: id.

update_a_microsoft_365_me_plan_by_id

Update a Microsoft Planner plan by id. Returns: id, title, owner, createdBy, createdDateTime, context. Required: id, etag_value.

delete_a_microsoft_365_me_plan_by_id

Delete a Microsoft Planner plan by id. Returns an empty 204 response on success. Required: id, etag_value.

microsoft_365_drive_item_download_download

Download the raw content of a file drive item from a Microsoft site's drive. Returns the file's binary content as a stream (application/octet-stream) — an opaque file payload with no JSON fields. Required: site_id, drive_id, item_id.

list_all_microsoft_365_drives

List the drives (document libraries) of a Microsoft site. Returns drive records including id. Required: site_id.

list_all_microsoft_365_drive_items

List Microsoft SharePoint drive items in a drive folder. Returns each driveItem with its id, name, size, file/folder facet, parent info, and the expanded listItem with content-type-specific SharePoint fields. Required: site_id, drive_id, and item_id (defaults to 'root' to list from the drive root).

get_single_microsoft_365_drive_item_by_id

Get a single Microsoft SharePoint drive item by id within a site's drive. Returns the driveItem resource including its id plus the resource's remaining properties. Required: id, site_id, drive_id.

microsoft_365_drive_items_download

Download the contents of a Microsoft drive item. Returns the raw file binary stream rather than a JSON object. Required: path (the driveItem's download URL).

microsoft_365_drive_item_export_download

Download the content of a Microsoft Graph drive item (file) that lives in a drive under a site, converted to the specified format. Returns the raw binary content stream of the file — not a JSON object. Required: site_id, drive_id, item_id, format.

get_single_microsoft_365_drive_items_v_2_by_id

Get a single item (file or folder) in a Microsoft drive by id. Returns the driveItem including its id, content stream, and the expandable children, permissions, and subscriptions relationships. Required: drive_id, id.

list_all_microsoft_365_drive_items_v_2

List the immediate children of a folder in a Microsoft drive; item_id defaults to 'root' to list the drive's top-level items. Each child is a driveItem with its SharePoint list metadata expanded. Returns: id, name, description, size, eTag, cTag, webUrl, createdDateTime, lastModifiedDateTime, parentReference, createdBy, lastModifiedBy. Required: drive_id, item_id.

list_all_microsoft_365_group_members

List the direct members of a Microsoft group. Returns directory objects including id, @odata.type, displayName, mail, and userPrincipalName — fields vary by member type (user, group, device, service principal, or organizational contact). This operation is not transitive. Required: group_id.

list_all_microsoft_365_sign_ins

List Microsoft Entra sign-in audit logs for the tenant, including interactive and successful federated sign-ins, with the most recent events returned first. Returns sign-in records with their id, user info, app details, sign-in status, and createdDateTime. No required parameters.

list_all_microsoft_365_sites

List all available Microsoft Graph (SharePoint) sites in the organization. Returns each site with id, siteCollection, webUrl, displayName, and lastModifiedDateTime; use search to find sites matching given keywords.

get_single_microsoft_365_site_by_id

Get the SharePoint site linked to a Microsoft Graph eDiscovery custodian's siteSource by id. Returns: id, description, name, error, root, analytics, columns, drive, drives, items, lists, onenote, operations, pages, permissions, sites. Required: id, ediscovery_case_id, ediscovery_custodian_id.

microsoft_365_sites_using_path

Get a Microsoft Graph (SharePoint) site by its address rather than by id. Returns the site's properties, including id, siteCollection, webUrl, displayName, name, description, createdDateTime, lastModifiedDateTime, and sharepointIds. Required: hostname and server_relative_path.

list_all_microsoft_365_site_permissions

List the permission objects associated with a Microsoft SharePoint site. Returns: id. Required: site_id. Beta endpoint.

list_all_microsoft_365_web_parts

List the web parts on a SharePoint site page in Microsoft Graph. Returns the collection of web part records from the page, each including its id. Required: site_id, page_id.

microsoft_365_web_parts_download

Download the raw content of a resource from Microsoft at the given path, resolved against the given base URL. Returns the binary file stream rather than a JSON object. Required: path, base.

list_all_microsoft_365_site_pages

List the site pages in a Microsoft Graph site's site pages list. Returns each page record with its id and the sitePage attribute fields defined by Microsoft Graph. Required: site_id.

get_single_microsoft_365_site_page_by_id

Get a single site page's metadata from a Microsoft Graph site's site pages list by id. Returns the sitePage record with its id and the sitePage attribute fields defined by Microsoft Graph. Required: site_id, id.

list_all_microsoft_365_groups

List all groups in the Microsoft organization (excludes dynamic distribution groups). Returns each group's id, hasMembersWithLicenseErrors, and isArchived by default; pass $select to retrieve additional properties. Supports the $orderby, $select, and $expand OData query options.

get_single_microsoft_365_group_by_id

Get the properties and relationships of a Microsoft group by id. Returns: id, classification, description, mail, theme, visibility, calendar, conversations, drive, drives, events, extensions, members, onenote, owners, photo, photos, planner, settings, sites, team, threads. By default only a subset of the group's properties is returned; use $select for more (hasMembersWithLicenseErrors and…

list_all_microsoft_365_directory_roles

List the directory roles that are activated in the Microsoft Entra ID tenant. Returns each role's id, deletedDateTime, description, displayName, and roleTemplateId. Only activated roles are returned — use List directoryRoleTemplates for the full set of available roles.

list_all_microsoft_365_licenses

List the commercial subscriptions (license SKUs) that an organization has acquired in Microsoft. Returns each subscription's skuId and skuPartNumber. Supports OData $filter, $search, $orderby, $select, and $expand query options.

list_all_microsoft_365_user_drives

List the OneDrive and SharePoint drives available to a Microsoft Graph user by id. Returns each drive's id, driveType, name, webUrl, quota, and owner. Required: user_id. Supports $top, $skip, $search, $filter, $count, $orderby, $select, and $expand.

get_single_microsoft_365_user_drive_by_id

Get a single Microsoft OneDrive drive by id. Returns the drive entity including its id and the @odata.context metadata Microsoft Graph attaches to entity responses; use $select / $expand to limit or expand the properties returned. Required: id.

list_all_microsoft_365_user_drive_items

List the children of a drive item in a Microsoft OneDrive drive. Returns a collection of drive items including each item's id, file/folder/package facets, and the identity of the last person who modified it. Required: drive_id, item_id. item_id defaults to root to list the drive's top-level contents.

get_single_microsoft_365_user_drive_item_by_id

Get a single drive item from a Microsoft OneDrive drive by id. Returns: id, createdBy, createdDateTime, description, eTag, lastModifiedBy, lastModifiedDateTime, name, parentReference, webUrl, createdByUser, lastModifiedByUser, audio, bundle, content, cTag, deleted, file, fileSystemInfo, folder, image, location, malware, package, pendingOperations, photo, publication, remoteItem, root,…

microsoft_365_user_drive_items_download

Download the raw content of a Microsoft OneDrive drive item using a pre-authorized content path. Returns the file's binary content stream rather than a JSON object. Required: truto_path, truto_base.

list_all_microsoft_365_drive_item_permissions

List the permissions on a Microsoft Graph drive item. Returns permission resources, each including its id and the roles granted. Required: drive_id, item_id.

list_all_microsoft_365_admin_consent_permissions

List tenant-wide (admin-consented) delegated permission grants in Microsoft Entra ID. Returns each grant's id and its attributes — the grant fields defined by the oAuth2PermissionGrant schema, shaped further by $select and $expand. Grants are limited to the consentType 'AllPrincipals' slice.

list_all_microsoft_365_deleted_users

List users deleted from the Microsoft Entra directory (deleted items of type microsoft.graph.user). Returns each deleted user's id, displayName, userPrincipalName, mail, deletedDateTime, jobTitle, and account details.

list_all_microsoft_365_app_role_assignments

List the Microsoft app role assignments granted to a user (the application roles the user holds for an application). Returns each assignment's id, appRoleId, principalId, principalDisplayName, resourceDisplayName, and creationTimestamp. Required: user_id.

list_all_microsoft_365_search_users

List Microsoft Graph users in the tenant's directory. Returns each user's id, displayName, userPrincipalName, mail, jobTitle, businessPhones, and account state. Supports OData $filter, $search, $orderby, and $expand to refine results.

list_all_microsoft_365_service_principals

List the service principals registered in Microsoft Graph. Returns servicePrincipal records including id, token_type, scope, and access_token; results can also include agentIdentityBlueprintPrincipal records. $search and $count require the ConsistencyLevel header set to eventual.

list_all_microsoft_365_user_chat_messages

List all messages in a Microsoft Teams chat for a specific user. Returns chatMessage objects including id, chatId, messageType, body, from, createdDateTime, and lastModifiedDateTime. Required: user_id, chat_id.

list_all_microsoft_365_contacts

List contacts in the user's default Outlook contacts folder. Use folder-contacts for contacts in other folders. Returns: id, parentFolderId, displayName, givenName, surname, emailAddresses, mobilePhone, businessPhones, companyName, jobTitle, createdDateTime, lastModifiedDateTime.

get_single_microsoft_365_contact_by_id

Get a single Outlook contact by id, from any contact folder. Returns: id, parentFolderId, displayName, givenName, surname, emailAddresses, mobilePhone, businessPhones, companyName, jobTitle, businessAddress, categories. Required: id.

list_all_microsoft_365_contact_folders

List the top-level contact folders in the user's Outlook mailbox (the default Contacts folder is not included; its contacts come from the contacts resource). Returns: id, displayName, parentFolderId.

get_single_microsoft_365_contact_folder_by_id

Get a single Outlook contact folder by id. Returns: id, displayName, parentFolderId. Required: id.

list_all_microsoft_365_contact_child_folders

List the child folders of an Outlook contact folder. Returns: id, displayName, parentFolderId. Required: contact_folder_id.

list_all_microsoft_365_folder_contacts

List the contacts in a specific Outlook contact folder. Returns: id, parentFolderId, displayName, givenName, surname, emailAddresses, mobilePhone, businessPhones, companyName, jobTitle, createdDateTime, lastModifiedDateTime. Required: contact_folder_id.

Why Truto

Why use Truto’s MCP server for Microsoft 365

Other MCP servers give you a static tool list for one app. Truto gives you a managed, multi-tenant MCP infrastructure across 850+ integrations.

01

Auto-generated, always up to date

Tools are dynamically generated from curated documentation — not hand-coded. As integrations evolve, tools stay current without manual maintenance.

02

Fine-grained access control

Scope each MCP server to read-only, write-only, specific methods, or tagged tool groups. Expose only what your AI agent needs — nothing more.

03

Multi-tenant by design

Each MCP server is scoped to a single connected account with its own credentials. The URL itself is the auth token — no shared secrets, no credential leaking across tenants.

04

Works with every MCP client

Standard JSON-RPC 2.0 protocol. Paste the URL into Claude, ChatGPT, Cursor, or any MCP-compatible agent framework — tools are discovered automatically.

05

Built-in auth, rate limits, and error handling

Tool calls execute through Truto’s proxy layer with automatic OAuth refresh, rate-limit handling, and normalized error responses. No raw API plumbing in your agent.

06

Expiring and auditable servers

Create time-limited MCP servers for contractors or automated workflows. Optional dual-auth requires both the URL and a Truto API token for high-security environments.

Unified APIs

Unified APIs for Microsoft 365

Skip writing code for every integration. Use Truto’s category-specific Unified APIs out of the box or customize the mappings with AI.

Unified HRIS API

Employees

Represents an employee in HRIS

View Docs

Unified Knowledge Base API

Page-Content

Represents the content of a page

View Docs

Pages

Represents the pages, posts, articles in a knowledge base

View Docs

Spaces

Represents the high level grouping of pages in a knowledge base

View Docs

Unified Instant Messaging API

Channels

Channels are a way to group the communication happening between users in the source application. Channels can be used for group messaging, team messaging, etc.

View Docs

Members

Members are users, apps, bots and integrations part of the organization. To differentiate between the type of member, use the `type` attribute.

View Docs

Messages

Messages are the communication between users in the source application.

View Docs

Workspaces

Workspaces represent concepts like teams, workspaces, projects in apps that support them

View Docs

Unified User Directory API

Activities

Activities are the actions performed by users in the source application.

View Docs

Groups

Groups are a collection of users in the source application. In some applications, they might also be called Teams.

View Docs

Licenses

Licenses represent concepts like user seats in apps that support them

View Docs

Roles

The Role object represents a role of a User.

View Docs

Users

The User object represents a User.

View Docs

Workspaces

Workspaces represent concepts like teams, workspaces, projects in apps that support them

View Docs

Unified File Storage API

Drive-Items

Drive Items are the files and folders present in a file storage system. These items are usually part of a Drive. You can differentiate between files and folders using the type attribute.

View Docs

Drives

Drives is a collection of files and folders. They could have multiple Drive Items within them. Users could have multiple Drives accessible to them in a file storage system.

View Docs

Permissions

Permissions can answer your questions around which User has access to do what on a Drive Item or a Drive.

View Docs

Users

Users represent the people using the underlying file storage system.

View Docs

Workspaces

Workspaces represent the top-level subdivision in a file storage system. They usually have their own set of drives, groups and users. Some of the usual terminologies used by the products for the top-level subdivision are projects, bases, spaces, workspace, etc.

View Docs

Unified Single Sign-On API

App Users

AppUsers represent the users assigned to an application.

View Docs

Apps

Applications represent the applications that are registered with the SSO service.

View Docs

Unified Ticketing API

Attachments

Attachments are the files associated with a ticket or a comment.

View Docs

Collections

Tickets and contacts can be grouped into Collections. Collection resource usually maps to the various grouping systems used in the underlying product. Some examples are lists, projects, epics, etc. You can differentiate between these grouping systems using the type attribute of a Collection.

View Docs

Ticket Priorities

Ticket Priorities represent the intended order in which the Tickets should be worked on. Some products provide customizing the Ticket Priorities.

View Docs

Tickets

Core resource which represents some work that needs to be carried out. Tickets are usually mapped to issues, tasks, work items, etc. depending on the underlying product.

View Docs

Users

Users represent the people using the underlying ticketing system. They are usually called agents, team members, admins, etc.

View Docs

Workspaces

Workspaces represent the top-level subdivision in a ticketing system. They usually have their own set of settings, tickets, statuses, priorities and users. Some of the usual terminologies used by the products for the top-level subdivision are projects, bases, spaces, workspace, etc. A Workspace could belong to an Organization.

View Docs

Unified Search API

Search

Search endpoint for all the apps.

View Docs

How It Works

From zero to integrated

Go live with Microsoft 365 in under an hour. No boilerplate, no maintenance burden.

01

Link your customer’s Microsoft 365 account

Use Truto’s frontend SDK to connect your customer’s Microsoft 365 account. We handle all OAuth and API key flows — you don’t need to create the OAuth app.

02

We handle authentication

Don’t spend time refreshing access tokens or figuring out secure storage. We handle it and inject credentials into every API request.

03

Call our API, we call Microsoft 365

Truto’s Proxy API is a 1-to-1 mapping of the Microsoft 365 API. You call us, we call Microsoft 365, and pass the response back in the same cycle.

04

Unified response format

Every response follows a single format across all integrations. We translate Microsoft 365’s pagination into unified cursor-based pagination. Data is always in the result attribute.

FAQs

Common questions about Microsoft 365 on Truto

Authentication, rate limits, data freshness, and everything else you need to know before you integrate.

How does authentication work for Microsoft 365 integrations through Truto?

Truto handles the full OAuth 2.0 flow with Microsoft Entra ID. Depending on the use case, your customers' end users can authenticate with delegated permissions (accessing only their own data) or a tenant admin can grant app-only permissions for organization-wide access. Truto manages token refresh and storage so you don't have to.

Which Microsoft 365 services are covered by Truto's Unified APIs?

Truto maps Microsoft 365 data across multiple Unified APIs: User Directory (Entra ID users, roles, licenses), File Storage (OneDrive and SharePoint drives, files, permissions), Instant Messaging (Teams workspaces, channels, messages, members), Knowledge Base (SharePoint pages and sites), Ticketing, Single Sign-On, HRIS (employee data), and Search. The underlying data comes primarily from the Microsoft Graph API.

How does Truto handle Microsoft Graph API rate limits and pagination?

Truto abstracts away Microsoft Graph's throttling and pagination. API responses are automatically paginated using cursor-based pagination, and Truto manages retry logic with exponential backoff when Graph returns 429 (Too Many Requests) responses, so your application doesn't need to implement this directly.

Can I access both delegated (per-user) and app-only (tenant-wide) data?

Yes. Truto supports both permission models. Delegated access is ideal when your end user connects their own Microsoft 365 account to access their personal files or calendar. App-only access is used when a tenant admin grants your app broad permissions to sync the entire corporate directory, all SharePoint sites, or all Teams channels across the organization.

What if I need a Microsoft 365 capability that isn't in the current Unified API resources?

Truto builds integration tooling on request. If you need access to Microsoft 365 data or actions — such as Outlook email, calendar events, or Planner tasks — that aren't yet mapped to a Unified API resource, Truto's team can add support. You can also use Truto's proxy mode to call any Microsoft Graph endpoint directly while still benefiting from Truto-managed auth.

Does Truto support real-time change detection from Microsoft 365?

Microsoft Graph supports webhooks (change notifications) and delta queries for incremental data sync. Truto can leverage these mechanisms to keep your data fresh without full re-syncs, reducing API call volume and ensuring near-real-time updates for resources like users, drive items, and messages.

From the Blog

Microsoft 365 integration guides

Deep dives, architecture guides, and practical tutorials for building Microsoft 365 integrations.

Microsoft 365

Get Microsoft 365 integrated into your app

Our team understands what it takes to make a Microsoft 365 integration successful. A short, crisp 30 minute call with folks who understand the problem.