AI agent for Microsoft 365 service desk tickets
Mizo connects to your clients' Microsoft 365 tenants through GDAP. Today, the End User Verification Agent uses that connection to prove who is behind a ticket with a Microsoft Authenticator push or a sign-in link. User, license and mailbox resolution are rolling out next.
- Status
- Live · resolution rolling out
- Connection
- GDAP delegated access, scoped per client tenant
- Works in
- ConnectWise PSA · Autotask · HaloPSA
- Agents
- End User Verification Resolution (rolling out)
About Microsoft 365: Microsoft 365 is Microsoft's cloud suite for identity (Entra ID), email (Exchange Online) and collaboration, and the source of a large share of MSP tickets.
What Mizo does with Microsoft 365
Identity comes first: before anyone resets a password or changes access, Mizo proves the request is real. Resolution builds on that.
Authenticator MFA push
Before a password reset or access change, Mizo sends a Microsoft Authenticator push to the device already registered for the requester's account, never to a number or address supplied in the ticket.
Sign-in link verification
When a push isn't practical, the requester gets a link and proves who they are by signing in with their own Microsoft 365 account.
Evidence written to the ticket
The verification method, result and time are recorded on the ticket in your PSA, so you can show a client or an auditor exactly how a request was verified.
Rolling out: user and license requests
Resolving the requester in Entra ID and handling common user and license changes from the ticket, rolling out from November 2026.
Rolling out: mailbox requests
Shared mailbox access, forwarding and similar Exchange Online requests, run at the autonomy level you set per client, rolling out from November 2026.
What's live today
End-user verification (Microsoft Authenticator push and sign-in link) is live. Microsoft 365 user, license and mailbox resolution is rolling out from November 2026. Ask us about early access.
How the Microsoft 365 connection works
Mizo runs in recommendation mode first, writing its reasoning to each ticket, and moves to autonomous handling only where you allow it.
Connect through GDAP
Mizo reaches each client tenant through Granular Delegated Admin Privileges with scoped roles. No global admin accounts, no shared credentials.
Choose clients and request types
Enable Microsoft 365 per client and decide which requests require verification, such as password resets, MFA changes or access requests.
Start in recommendation mode
Mizo writes its verification result and reasoning to the ticket. Technicians stay in control until you decide to let it run on its own.
Mizo and Microsoft 365: common questions
Does Mizo need global admin in my clients' tenants?
No. Mizo connects through GDAP with scoped roles, client by client. You decide which client tenants are enabled.
How does Microsoft Authenticator verification work?
Mizo triggers an MFA push to the Authenticator app already registered on the requester's account. The user approves it on their own device and the result is logged on the ticket. Contact details supplied in the ticket itself are never used as the verification channel.
Can Mizo reset passwords or change licenses in Microsoft 365 today?
Not yet. User, license and mailbox resolution is rolling out from November 2026. Today the Microsoft 365 connection powers end-user verification. Contact us to join early access.
What if the user doesn't have Microsoft Authenticator set up?
Mizo can send a sign-in link instead, where the user authenticates with their Microsoft 365 account. For clients standardized on Duo, Mizo can use a Duo Push.
Agents and pages that work with Microsoft 365
End User Verification Agent
Proves who is behind a ticket before any account change.
Resolution Agent
Executes approved fixes at the autonomy level you set.
Mizo for Duo
Duo Push verification before sensitive changes.
Agentic L1 for MSPs
Automating password resets, access requests and L1 work.