Integrations

Helios connects to the stack an MSP actually runs: Microsoft 365 and Defender per client, backup products at the agent level, notification channels, and remote access built in rather than bolted on.

Microsoft 365

Connecting a client takes one approval, not an app registration. Click Connect on the client's Microsoft 365 card (or send the link to their Global Administrator), they approve once in their own tenant, and the card fills in. Nothing is created or configured in their Azure portal. Helios then polls Microsoft Graph for the things you get asked about: licence counts and assignment, MFA coverage per user, mailbox and OneDrive quota pressure, and inactive accounts, plus one-click account actions for a leaver: reset password, reset MFA, block sign-in and revoke every session. Devices link to their M365 user via UPN.

Microsoft Defender

Defender rides the same approval: once Microsoft 365 is connected, one click on the Defender card switches it on. It is an opt-in rather than automatic, because a tenant without a Defender licence has nothing to poll. Connected, Helios turns Defender threats into tickets on the affected client, reads per-device security posture, and mirrors Defender Vulnerability Management: every open critical and high CVE across the client's machines, aggregated per vulnerability with the exposed device count, on the Security page, the same content Microsoft emails tenant admins, where your technicians actually work. Clients connected the older way, with their own app registration, keep working.

Backup monitoring

Two independent layers. Agents detect backup activity at the OS level: Windows Backup, Veeam, Acronis and other products that log through the Windows event system or VSS, with a backup staleness metric that alerts when a device has gone too long without a successful backup, with no vendor credentials needed. On top of that, direct Veeam and Acronis API connections read jobs as the vendor sees them, tracking when each job last produced a restore point rather than when it last ran, so a job that fails every night stops looking healthy.

Remote access

One click on an online device opens a remote desktop session in the browser. Remote access is part of the platform, self-hosted on our infrastructure, with no second vendor, licence or agent to manage. Sessions are initiated from Helios so access follows your Helios accounts and their 2FA.

QuickBooks Online and Xero

Connect QuickBooks Online or Xero under Settings → Accounting (standard Intuit or Xero sign-in; Helios stores tokens encrypted and only ever reads customers or contacts, service items or revenue accounts, and tax codes, and creates invoices). Map each Helios client to a customer in QuickBooks or a contact in Xero once, then push any month's billable time in as a draft invoice from the Billing page: one line per time entry, totals matching the CSV export exactly. Helios never emails invoices or deletes anything in your accounting package; you review and send from there.

See the whole path screen by screen, from an hour logged on a ticket to a draft invoice waiting for your approval.

Email and notifications

Your own systems

Anything else can integrate through the public API: scoped, documented REST over clients, devices, tickets and alerts.