Documentation

Microsoft 365 Copilot Setup

Connect a Microsoft 365 tenant so ZopNight can track Copilot seats, usage and cost. Lists the exact Microsoft Graph permissions, the admin role needed to approve them, and the optional billing role.

The Microsoft 365 Copilot integration shows how many Copilot seats you pay for, who uses them, and which seats sit idle. You find it under Costs → Reports → AI Spend → Seat licences. ZopNight only reads data. It never assigns or removes licences.

Before you start

NeedDetail
Microsoft 365 Copilot licencesThe tenant must hold at least one Copilot licence.
An admin who can grant consentA Global Administrator or Privileged Role Administrator.
A ZopNight AdminOnly Admins can connect or disconnect a tenant.
For prices (optional)A Microsoft Customer Agreement or Microsoft Partner Agreement billing account.

Application Administrator and Cloud Application Administrator can't grant Microsoft Graph application permissions, so they can't complete this setup.

You don't need to create an app registration or share a secret. ZopNight uses its own multi-tenant app and stores only your tenant ID.

Access to grant

Microsoft Graph application permissions

The admin approves these four read-only permissions on one consent screen. Each is the permission Microsoft lists for the API ZopNight calls.

PermissionWhy ZopNight needs it
Organization.Read.AllTenant name, licence SKUs and seat counts, renewal dates
User.Read.AllThe users who hold a Copilot licence
Reports.Read.AllCopilot usage per user, and Microsoft 365 activity
ReportSettings.Read.AllWhether reports hide user names

Microsoft's pages for each API, with the permission it needs:

Billing role (optional, for prices)

To show what each seat costs, grant the ZopNight app Billing account reader on your billing account. Billing profile reader on the right billing profile also works. See Billing roles for Microsoft Customer Agreements.

  1. In the Azure portal, open Cost Management + Billing and pick the billing account.
  2. Open Access control (IAM) and click Add.
  3. Choose the role, then search for the ZopNight app.

You can also assign it with the Billing Role Assignments API.

Tenant setting (for per-person usage)

Microsoft hides user names in reports by default. With names hidden, ZopNight can count seats but can't say which person is idle. To show names, a Global Administrator goes to Microsoft 365 admin center → Settings → Org settings → Services → Reports, clears Conceal user, group, and site names in all reports, and saves. See Show user, group, or site details in usage reports.

Set it up

  1. Start the connection

    In ZopNight, open Settings → Integrations → AI Seat Licences and click Connect on the Microsoft 365 Copilot tile.

  2. Sign in to Microsoft

    Sign in with a work account in the tenant you want to connect. ZopNight uses this step to learn which tenant it is.

  3. Approve the permissions

    Microsoft shows the consent screen with the four permissions above. A Global Administrator or Privileged Role Administrator approves it for the whole organisation.

  4. Wait for the first sync

    You return to ZopNight and see Microsoft 365 connected. Seat data appears after the next sync. Microsoft publishes Copilot usage within about 48 hours of the end of each day, so usage lags behind seat counts.

To connect more tenants, use Connect another tenant on the same tile. Each tenant can belong to only one ZopNight organisation.

Disconnect and remove access

Settings → Integrations → AI Seat Licences → Disconnect removes the tenant and its data from ZopNight. It changes nothing in your Microsoft tenant. To remove access fully:

  1. Delete the ZopNight enterprise app: in the Microsoft Entra admin center, open Enterprise apps → All applications, pick ZopNight, open Properties and click Delete. This needs a Cloud Application Administrator, an Application Administrator, or the app's owner.
  2. Remove the billing role from the ZopNight app under Cost Management + Billing → Access control (IAM), if you granted it.

Troubleshooting

ProblemCause and fix
Consent fails, or the tile never connectsThe approver wasn't a Global or Privileged Role Administrator. Ask one to connect again.
Seat counts show, but no usageMicrosoft hasn't published usage yet. Wait up to two days after connecting.
Usage is shown without namesReports hide user names. Change the tenant setting above.
No pricesNo billing role was granted, or the account isn't a Customer or Partner Agreement.
Tenant already connected to a different ZopNight organisationAnother ZopNight organisation owns this tenant. Contact support to move it.