Microsoft 365 Copilot Setup
Connect a Microsoft 365 tenant so ZopNight can track Copilot seats, usage and cost. Lists the exact Microsoft Graph permissions, the admin role needed to approve them, and the optional billing role.
The Microsoft 365 Copilot integration shows how many Copilot seats you pay for, who uses them, and which seats sit idle. You find it under Costs → Reports → AI Spend → Seat licences. ZopNight only reads data. It never assigns or removes licences.
Before you start
| Need | Detail |
|---|---|
| Microsoft 365 Copilot licences | The tenant must hold at least one Copilot licence. |
| An admin who can grant consent | A Global Administrator or Privileged Role Administrator. |
| A ZopNight Admin | Only Admins can connect or disconnect a tenant. |
| For prices (optional) | A Microsoft Customer Agreement or Microsoft Partner Agreement billing account. |
Application Administrator and Cloud Application Administrator can't grant Microsoft Graph application permissions, so they can't complete this setup.
You don't need to create an app registration or share a secret. ZopNight uses its own multi-tenant app and stores only your tenant ID.
Access to grant
Microsoft Graph application permissions
The admin approves these four read-only permissions on one consent screen. Each is the permission Microsoft lists for the API ZopNight calls.
| Permission | Why ZopNight needs it |
|---|---|
Organization.Read.All | Tenant name, licence SKUs and seat counts, renewal dates |
User.Read.All | The users who hold a Copilot licence |
Reports.Read.All | Copilot usage per user, and Microsoft 365 activity |
ReportSettings.Read.All | Whether reports hide user names |
Microsoft's pages for each API, with the permission it needs:
Organization.Read.All: organization, subscribedSkus, subscriptionsUser.Read.All: List usersReports.Read.All: Copilot usage, user count trend, active usersReportSettings.Read.All: Get adminReportSettings
Billing role (optional, for prices)
To show what each seat costs, grant the ZopNight app Billing account reader on your billing account. Billing profile reader on the right billing profile also works. See Billing roles for Microsoft Customer Agreements.
- In the Azure portal, open Cost Management + Billing and pick the billing account.
- Open Access control (IAM) and click Add.
- Choose the role, then search for the ZopNight app.
You can also assign it with the Billing Role Assignments API.
Tenant setting (for per-person usage)
Microsoft hides user names in reports by default. With names hidden, ZopNight can count seats but can't say which person is idle. To show names, a Global Administrator goes to Microsoft 365 admin center → Settings → Org settings → Services → Reports, clears Conceal user, group, and site names in all reports, and saves. See Show user, group, or site details in usage reports.
Set it up
Start the connection
In ZopNight, open Settings → Integrations → AI Seat Licences and click Connect on the Microsoft 365 Copilot tile.
Sign in to Microsoft
Sign in with a work account in the tenant you want to connect. ZopNight uses this step to learn which tenant it is.
Approve the permissions
Microsoft shows the consent screen with the four permissions above. A Global Administrator or Privileged Role Administrator approves it for the whole organisation.
Wait for the first sync
You return to ZopNight and see Microsoft 365 connected. Seat data appears after the next sync. Microsoft publishes Copilot usage within about 48 hours of the end of each day, so usage lags behind seat counts.
To connect more tenants, use Connect another tenant on the same tile. Each tenant can belong to only one ZopNight organisation.
Disconnect and remove access
Settings → Integrations → AI Seat Licences → Disconnect removes the tenant and its data from ZopNight. It changes nothing in your Microsoft tenant. To remove access fully:
- Delete the ZopNight enterprise app: in the Microsoft Entra admin center, open Enterprise apps → All applications, pick ZopNight, open Properties and click Delete. This needs a Cloud Application Administrator, an Application Administrator, or the app's owner.
- Remove the billing role from the ZopNight app under Cost Management + Billing → Access control (IAM), if you granted it.
Troubleshooting
| Problem | Cause and fix |
|---|---|
| Consent fails, or the tile never connects | The approver wasn't a Global or Privileged Role Administrator. Ask one to connect again. |
| Seat counts show, but no usage | Microsoft hasn't published usage yet. Wait up to two days after connecting. |
| Usage is shown without names | Reports hide user names. Change the tenant setting above. |
| No prices | No billing role was granted, or the account isn't a Customer or Partner Agreement. |
| Tenant already connected to a different ZopNight organisation | Another ZopNight organisation owns this tenant. Contact support to move it. |