Read-only permissions
Directory.Read.All, Policy.Read.All and Reports.Read.All suffice. The connector cannot change anything in the tenant.
Continuously check the tenant for misconfigurations
The connector reads the tenant via Microsoft Graph: directory, policies, reports, security events and applications. It needs an app registration with read-only application permissions and admin consent; alternatively the instance’s central Microsoft sign-in can be reused. Every violation becomes a finding with severity, evidence and remediation guidance. Nothing is written back.
Vendor: Microsoft · learn.microsoft.com/graph
Directory.Read.All, Policy.Read.All and Reports.Read.All suffice. The connector cannot change anything in the tenant.
Each permission step is checked individually instead of just failing at the end.
We show you the connector live in your own environment – non-binding and free of charge.