Step-by-step instructions for turning on the Microsoft integration, so your members' Betterup® AI coach can draw on their role, team, calendar, and recent work.
Key takeaways
- Your BetterUp implementation contact activates setup for your organization. Members can't connect until your Microsoft administrator finishes the steps below.
- Individual members can then connect their own Microsoft account from the Integrations page on the BetterUp platform.
- Microsoft Work IQ must be turned on in your Microsoft tenant, and your organization needs a spending policy to cover usage.
Jump to: Before you start | Setup Instructions | What BetterUp accesses | FAQs
Before you start
| Requirement | Detail |
| Administrator roles |
|
| Azure subscription | You need an Azure subscription linked to the billing account you'll charge for Work IQ usage. The spending policy in step 3 requires it. If you don't have one, you can create one during setup. |
| BetterUp setup | Your BetterUp implementation contact turns on setup for your organization and emails you the approval link you'll use in step 4. |
Setup Instructions: Step by step
Step 1: Verify administrator permissions
Confirm you hold the roles listed above. If your organization doesn't allow permanent Global Administrator access, you can turn the role on temporarily through Microsoft Entra Privileged Identity Management (PIM), then turn it off when setup is done. After setup, no admin role is needed to keep the integration running.
Step 2: Enable Work IQ for your tenant
This step registers Work IQ in your Microsoft tenant, so apps like BetterUp can request access to it. Microsoft calls this creating a service principal. It's a one-time, organization-wide setup, and no data is shared. You'll approve data access separately in step 4.
- Open Microsoft Graph Explorer and sign in with an administrator account.
- Set the method to POST and the URL to https://graph.microsoft.com/v1.0/servicePrincipals. Enter the URL before the next step, because Graph Explorer surfaces the relevant permissions based on it.
- Select Modify permissions and consent to Application.ReadWrite.All. This applies to your Graph Explorer session only and does not change organization-wide permissions.
-
Enter this app ID in the request body and select Run
{ "appId": "fdcc1f02-fc51-4226-8753-f668596af7f7" }
A 201 Created response confirms success. A conflict error means the service principal already exists, which is also fine. Continue to step 3.
For more details, see Microsoft's documentation: Enable your tenant for Work IQ.
Step 3: Create a spending policy
Work IQ is billed by consumption in Microsoft Copilot Credits.
- Sign in to the Microsoft 365 admin center as a Global or Billing Administrator.
- Go to Copilot > Cost Management. If usage-based billing has never been activated, select Get Started. Otherwise open the Configuration tab and select Add spending policy. This is where you will configure the scope, limit, and alerts for your spending policy.
- Services. Select Work IQ API. Turn Auto-apply new services OFF, so this policy only covers Work IQ and doesn't pick up other paid services.
- Review and select Create spending policy. The policy is created right away, but it can take 15 to 30 minutes to reach each member.
For more details, see Microsoft's documentation: Managing AI experiences enabled by usage-based billing.
Step 4: Grant consent for your organization
Anyone with one of these roles can complete this step:
- Global Administrator
- Privileged Role Administrator
- Cloud Application Administrator
- Application Administrator.
If you don't have access to one of these roles, we recommend forwarding the approval link to someone who does.
Your BetterUp implementation contact will send an approval link by email. Open it and sign in with your work account. You don't need a BetterUp account, and you won’t be asked to share any keys, credentials, or tenant IDs with BetterUp.
Microsoft shows a consent page with BetterUp's app name and the one permission it's requesting. Review and select Accept for your organization.
If the person completing this step doesn't hold one of the roles above, forward the link to someone who does. Members cannot connect until this step is complete.
Step 5: Tell your members
Once consent is granted, each member connects their own account from their Integrations page in BetterUp. It takes one click, and they won't need to approve anything, because your consent in step 4 already covers them. You can't connect members on their behalf, so let them know it's available.
Share the member article with your population: Connecting your Microsoft account to BetterUp.
What BetterUp accesses
BetterUp requests one delegated permission: WorkIQAgent.Ask. This allows BetterUp to ask Work IQ questions on behalf of the consenting, signed-in member.
Every request runs as the signed-in member and returns only what that member can already see, to help the BetterUp platform understand more about the user's role, calendar, and team. There is nothing to configure and nothing to select: approving this one permission is the entire consent step.
FAQs
What do members see before we enable this?
Before your BetterUp implementation contact opens up setup, nothing: the integration is not listed and no prompt appears anywhere in the product.
Does connecting give BetterUp access to anything a member cannot already see?
No. Microsoft applies the member's own permissions to every request. Sensitivity labels, restricted sites and private content behave exactly as they do elsewhere in Microsoft 365.
Can a manager see a direct report's work context?
No. This integration feeds each member's own coaching experience only. It creates no view for managers, HR or anyone else in your organization.
What happens if we revoke consent?
All members lose the integration at once. Existing directory facts already on their BetterUp profile remain; no new work context is retrieved.
A member says the connection failed immediately after they approved it. Why?
They are most likely not covered by a spending policy. Add their security group to a policy that includes Work IQ API, then wait 15 to 30 minutes.
A member connected successfully but the coach knows nothing about their work. Why?
Work IQ's index is still building. This is normal shortly after a tenant is enabled and usually resolves within 15 to 30 minutes. It can also mean the member genuinely has little recent Microsoft 365 activity.
Jump to: Before you start | Setup Instructions | What BetterUp accesses | FAQs