> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tenantcore.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect a Microsoft 365 Tenant

> Connect a Microsoft 365 tenant you already own or administer to TenantCore.

# Connect a Microsoft 365 Tenant

TenantCore starts with a Microsoft 365 tenant that you already own or are authorized to administer.

The connection uses Microsoft's authorization flow. You do not manually enter a Global Administrator password into TenantCore.

## Before you begin

Make sure:

* you can sign in to the Microsoft 365 tenant
* you are authorized to grant the permissions TenantCore requests
* the tenant has the Microsoft 365 / Exchange capabilities required for the workflows you plan to use
* you have an available TenantCore tenant slot

## Connect the tenant

1. Open **Tenants**.
2. Choose **Connect tenant**.
3. TenantCore opens the Microsoft authorization flow.
4. Sign in with an account authorized to grant the requested permissions.
5. Review the Microsoft consent screen.
6. Complete consent.
7. Return to TenantCore.

TenantCore then discovers the tenant and creates the TenantCore tenant resource.

## What TenantCore verifies

After connection, TenantCore can check supported readiness such as:

* tenant access
* Exchange licence availability
* required application permissions
* supported service-health state

The tenant must exist as a TenantCore-owned resource before domains, mailboxes, DNS automation, or public API operations can be performed against it.

## Re-consent or refresh application access

If TenantCore later requires additional Microsoft permissions, use the tenant's **Resync app** / refresh-access workflow.

This reopens Microsoft consent for the same connected tenant. It does not consume another tenant slot.

## If connection fails

Check:

* you signed in to the intended Microsoft tenant
* the signing account can grant the requested permissions
* browser popup blocking is not preventing Microsoft authorization
* the tenant is not already attached to another conflicting TenantCore resource

If the Microsoft authorization flow is interrupted, start the connection again from TenantCore rather than manually constructing a Microsoft consent URL.

## Security note

Knowing a Microsoft tenant GUID is not enough to operate against that tenant through TenantCore.

TenantCore ties every connected tenant to the authenticated TenantCore account before supported actions are allowed.
