Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Connect Microsoft 365 and Google Workspace license intelligence. Display subscription products, reported capacity, assigned users and returned role indicators without changing a vendor license. Current availability: Implemented; each company supplies and approves its own read-only provider application. Before you start. A LastStop Connect company Owner, Administrator or Billing administrator with Vendor licenses management permission. The protected integration vault and a dedicated provider application belonging to that company. Microsoft Graph application permissions LicenseAssignment.Read.All and User.Read.All with tenant administrator consent, or a Google delegated service account for Directory user read-only and License Manager access. Step 1. Open Companies > company > Vendor licenses. The same tenant-scoped page is available to eligible customer roles in their company portal. Step 2. For Microsoft 365, create a dedicated Entra application, add LicenseAssignment.Read.All and User.Read.All application permissions, grant administrator consent, and create a time-limited client secret. Paste the tenant ID, client ID and secret into the Microsoft 365 connection form. To include direct active directory roles and their allowed actions, also grant RoleManagement.Read.Directory and select Include direct active Entra directory roles. Group-derived, eligible PIM and application permissions are not part of this view. Step 3. For Google Workspace, create a dedicated service account and enable domain-wide delegation. Authorize admin.directory.user.readonly and apps.licensing for the service account client ID. Enter the service-account email, delegated administrator email, private key and applicable License Manager product IDs. Google-Apps is the default starting product ID. Enter the actual Customer ID from Google Admin > Account > Account settings > Profile (for example C01234567). The licensing endpoint does not use my_customer. Google offers no read-only licensing scope; LastStop limits inventory calls to GET and never exposes license mutations. Step 4. Save the protected credentials. Secrets are encrypted, never returned to the browser and replaced as a new revision when rotated. Step 5. Run Sync now after provider consent. The source moves through its recorded lifecycle state. A successful read replaces the complete snapshot atomically; a failed provider call or failed database write preserves the previous snapshot. Step 6. Search by user, email, product, SKU or returned permission. Product capacity depends on what the provider API returns; Google assignment feeds do not always include purchased capacity. Step 7. To stop a source, choose Pause or move it to Trash. Restore returns it with synchronization paused. Choose Resume, then Sync now when ready. Resume does not contact the provider. Permanent deletion erases only the local encrypted credential and cached inventory. Now verify the result. A user from another company receives access denied and cannot query this company ID. No API route or interface offers assign, unassign, purchase or cancel for an external vendor license. Provider secrets never appear in the response, activity detail or browser after saving. Product totals and assigned-user counts reconcile with the provider administration console for the same tenant and sync time. Pause or delete a connection during a sync: a late result must not overwrite the local lifecycle state. A failed database write must preserve the previous complete snapshot. A restored or paused connection has a visible Resume action. Resume alone must not send a provider request or modify a vendor account. If you get stuck. Microsoft 401 or 403: confirm the tenant ID, secret expiry, application—not delegated—permissions and completed administrator consent. Google 401 or 403: confirm domain-wide delegation, exact OAuth scopes, delegated administrator account and enabled Admin SDK and Enterprise License Manager APIs. A failed sync preserves the last complete snapshot. Rotate or correct credentials, then run Sync again; do not broaden permissions to include write access. For Okta, OneLogin, Salesforce, Adobe, Atlassian, Slack and Zoom, use the separate provider articles below. Their inventory scope differs; application assignments are not necessarily paid licenses. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.