Integrations
One overlay. Every console.
Pick a vendor to watch what OA6 does there. Microsoft works today. The others are previews of what is being built, and each one says how far along it is.
By vendor
Choose a vendor
OA6 acts only as the signed-in administrator. Where a vendor has no sign-in that names the person, OA6 reads what it can and hands you the fix in that vendor's own console.
Microsoft
Works today
Entra ID · Intune · Defender XDR · Defender for Endpoint · Defender for Identity · Defender for Office 365 · Defender for Cloud · Purview · Azure RBAC
OA6 reads the Microsoft page you have open, puts identity, device and security readings on one card, explains them, and makes the change you approve, as you.
Status Microsoft works today. Incidents and alerts come from Defender XDR, so a detection raised by Defender for Identity, Defender for Office 365, Defender for Endpoint or Defender for Cloud is named by the product that raised it, and OA6 triages any of them as you. Azure resources are read-only: OA6 shows who has access, what protects them and what Defender for Cloud makes of them, and changes nothing there.
Microsoft, step by step
ServiceNow
In preview
Users · CMDB assets · Incidents
OA6 pairs the ServiceNow user, asset and ticket with the Entra account and Intune device they describe, and proposes the fix on the Microsoft side when the two disagree. Each admin signs in with their own ServiceNow account, and OA6 only reads ServiceNow.
Status ServiceNow is in preview and is not available yet. It is read-only on ServiceNow, has not yet run against a real ServiceNow instance, and the changes it proposes are made in Microsoft, with your approval.
ServiceNow, step by step
Okta
In preview
Users · Sessions · Factors · System Log
OA6 pairs each Okta user with their Entra account and shows where the two disagree, such as an account blocked in Entra that still has live Okta sessions. Each admin signs in with their own Okta account, and OA6 only reads Okta.
Status Okta is in preview and is not available yet. It will be read-only on Okta; acting in Okta from OA6 is planned.
Okta, step by step
In preview
Google Workspace · ChromeOS · Google Cloud
One Google sign-in covers Workspace users and Alert Center, ChromeOS devices, and Google Cloud access. OA6 puts them on one card beside the same person in Entra. It only reads Google.
Status Google Workspace, ChromeOS and Google Cloud are in preview and are not available yet. They will be read-only; acting in Google from OA6 is planned.
Google, step by step
Jamf
In preview
Jamf Pro computers · Groups · Policies
OA6 puts each Mac in Jamf Pro beside its user in Entra, with its groups and the policies in scope. Each admin signs in with their own Jamf Pro account, and OA6 only reads Jamf.
Status Jamf is in preview and is not available yet. It will be read-only on Jamf; admins who sign in to Jamf only through single sign-on cannot use it.
Jamf, step by step
CrowdStrike
In preview
Falcon hosts · Alerts · Sensor status
On an Intune device, OA6 finds the same host in CrowdStrike Falcon and flags where the two disagree: an open High or Critical alert on a device Intune calls compliant, a host Falcon has contained, or a sensor that has gone silent. Each admin creates their own read-only API client, following setup steps shown on the connection card, and it is kept for the browser session only. CrowdStrike's own logs name that client, not the person. OA6 only reads CrowdStrike.
Status CrowdStrike is in preview and is not available yet. It is read-only on CrowdStrike, and has not yet been tested against a real Falcon tenant.
CrowdStrike, step by step
Darktrace
In preview
Devices · Model breaches
On an Intune device, OA6 finds the same device in Darktrace by hostname and MAC address and shows its model breaches from the last 7 days. It flags a device Entra has disabled that Darktrace still saw this week, and a device Intune calls compliant that has a high-scoring breach. Each admin pastes their own Darktrace token pair, kept for the browser session only. Darktrace's own logs record the token, not the person. OA6 only reads Darktrace.
Status Darktrace is in preview and is not available yet. It is read-only on Darktrace, and has not yet been tested against a real Darktrace appliance.
Darktrace, step by step
Proofpoint
In preview
Targeted Attack Protection · Messages · URL clicks
On a person in Entra or Defender, OA6 shows their Proofpoint threats: malicious messages delivered or blocked, and malicious URL clicks permitted or blocked. Live threats join the same Alerts list as Microsoft's, sorted by priority, and when Proofpoint and Defender flag the same URL, file hash or sending IP, the card says Flagged by 2 vendors. It flags a threat still delivered to the inbox, a permitted malicious click on an account Entra rates low risk, and a Very Attacked Person with no MFA. Each admin pastes their own TAP service principal and secret, kept for the browser session only. Proofpoint's own logs name that credential, not the person. The connection card turns it on or off, tests it and signs out. OA6 only reads Proofpoint, because TAP's API is read-only; email removal goes through Defender.
Status Proofpoint is in preview and is not available yet. It is read-only on Proofpoint, and has not yet been tried on a real Proofpoint account.
Proofpoint, step by step
Mimecast
In preview
Targeted Threat Protection · URLs · Attachments · Impersonation
On a person in Entra or Defender, OA6 shows the last 7 days in Mimecast: malicious URL clicks, malicious attachments and impersonation attempts, with what Mimecast did about each. They join the same Alerts list as Microsoft's and Proofpoint's, and a threat more than one vendor saw is marked Flagged by N vendors. It flags a malicious click Mimecast allowed on an account Entra rates low risk, and a malicious attachment that was delivered. Each admin pastes the client ID and secret of an API application they created in the Mimecast console, which Mimecast runs with that admin's own roles. It needs Read on URL Protection, Attachment Protection and Impersonation Protection, and is kept for the browser session only. Mimecast's own logs name the application, not the person. The connection card turns it on or off, tests it and signs out. OA6 can also remove messages with a malicious attachment. You pick an attachment from this person's Mimecast detections, and Mimecast removes every message carrying that file from all protected mailboxes (last 7 days). It runs only after you approve it, it needs Edit on Threat Remediation in your own Mimecast role, and the reason Mimecast records names you, the time and the file hash. There is no undo.
Status Mimecast is in preview and is not available yet. It reads Mimecast, and removing messages with a malicious attachment is in preview too, behind the approval card. Neither has yet been tried on a real Mimecast account.
Mimecast, step by step
Cloudflare
In preview
Zero Trust users · WARP devices · Audit log
OA6 pairs each person and laptop with Cloudflare Zero Trust and shows where the two disagree: an account Entra has blocked that still has WARP devices enrolled, a disabled device still connecting through WARP, or what a risky account changed in Cloudflare this week. Each admin signs in with their own Cloudflare account, so Cloudflare's own audit log names the person, not a shared key. Read-only on Cloudflare for now.
Status Cloudflare is in preview and is not available yet. It is read-only on Cloudflare, and has not yet run against a real Cloudflare account.
Cloudflare, step by step
AWS
In preview
IAM Identity Center users · Accounts · Permission sets
OA6 pairs each IAM Identity Center user with their Entra account and shows what they can still reach in AWS, such as a person who left but still holds an administrator permission set. It only reads AWS.
Status AWS is in preview and is not available yet. It will be read-only on AWS, through IAM Identity Center.
AWS, step by step
Oracle
In preview
Oracle Cloud identity domains
OA6 pairs each user in an Oracle Cloud identity domain with their Entra account, with their groups and sign-in factors. It only reads Oracle Cloud, and starts with identity domains.
Status Oracle Cloud is in preview and is not available yet. It will be read-only, and covers identity domains only; the rest of Oracle Cloud is planned.
Oracle, step by step
Build in progress: Patch My PC and Tanium. Being built, not available yet, so neither has a walkthrough.
Illustrations with sample data. Northwind, its people and its devices are fictional. Microsoft, Entra, Intune, Defender, Purview and Azure are trademarks of the Microsoft group of companies, and every other product name here belongs to its owner. OA6 is not affiliated with, sponsored by or endorsed by any vendor shown.
Core features
Read, explain, approve, record
The path every vendor follows, shown on Microsoft, where it works today: fix a user, then a device.
Remediate a user
Remediate a device
Automations · Build in progress
From one incident to a rule, across platforms
Ask OA6 explains an incident that reaches past Microsoft. One approval contains it in Microsoft, the card lists what is still to do in each other console, and OA6 offers to keep the response as a draft rule. The second walkthrough tests a draft rule against past incidents and arms it. The trigger is automatic; whether the act is too is your choice at arming.
Ask OA6 across platforms
Test the draft rule, then arm it
Status Build in progress. Automations is not available yet, and the connections outside Microsoft are in preview. These walkthroughs show the current design, which may change before it ships.