Security & privacy

Permissions reference by module

Every application permission and directory role each module requests, with the reason, plus the delegated scopes used during onboarding and sign-in.

Who can do this
Everyone
Plan
All plans
Time
Reference

Module apps (application permissions)

Each module is a separate multi-tenant app with no secrets or certificates. Open a module to see its permissions.

Core (M365 Assessment – Core) · 23 read-only permissions
Permissions
PermissionResourceWhy we need it
Directory.Read.AllMicrosoft GraphUsers, groups, organization, SKUs, domains, directory roles, apps and service principals; the directory-role check for every module
Organization.Read.AllMicrosoft GraphOrganization, branding, subscriptions
AuditLog.Read.AllMicrosoft GraphSign-in activity, sign-in logs, MFA registration details
SecurityEvents.Read.AllMicrosoft GraphSecure Score (report cover)
Policy.Read.AllMicrosoft GraphConditional Access, authentication methods, security defaults, cross-tenant access
RoleManagement.Read.DirectoryMicrosoft GraphPIM eligibility / assignment schedules, role definitions
IdentityRiskyUser.Read.AllMicrosoft GraphRisky users
IdentityRiskEvent.Read.AllMicrosoft GraphRisk detections
IdentityRiskyServicePrincipal.Read.AllMicrosoft GraphRisky service principals
Agreement.Read.AllMicrosoft GraphTerms of use
AccessReview.Read.AllMicrosoft GraphAccess review definitions
DirectoryRecommendations.Read.AllMicrosoft GraphEntra recommendations
OnPremDirectorySynchronization.Read.AllMicrosoft GraphEntra Connect sync configuration
CrossTenantInformation.ReadBasic.AllMicrosoft GraphPartner tenant names in cross-tenant access
Synchronization.Read.AllMicrosoft GraphSCIM provisioning jobs
DeviceManagementManagedDevices.Read.AllMicrosoft GraphIntune managed devices
DeviceManagementConfiguration.Read.AllMicrosoft GraphCompliance / configuration profiles, update rings
DeviceManagementApps.Read.AllMicrosoft GraphIntune apps and app protection policies
DeviceManagementServiceConfig.Read.AllMicrosoft GraphAutopilot, connectors, APNs certificate
DeviceManagementRBAC.Read.AllMicrosoft GraphIntune multi-admin approval
DeviceManagementScripts.Read.AllMicrosoft GraphPlatform scripts and remediations
Reports.Read.AllMicrosoft GraphMicrosoft 365 usage reports (active users, Copilot usage)
ReportSettings.Read.AllMicrosoft GraphWhether usage reports conceal user names
Exchange & Security (M365 Assessment – Exchange & Security) · read-only + Global Reader
Permissions
PermissionResourceWhy we need it
Exchange.ManageAsAppOffice 365 Exchange OnlineApp-only sign-in to Exchange Online / Security & Compliance PowerShell. Grants no rights by itself: the Global Reader role limits it to view-only Get-* cmdlets
SecurityEvents.Read.AllMicrosoft GraphSecure Score and Secure Score control profiles (Defender chapter)
SecurityIdentitiesSensors.Read.AllMicrosoft GraphDefender for Identity sensor deployment and health
Organization.Read.AllMicrosoft GraphOrganization and subscribed SKUs (Defender licensing)
Domain.Read.AllMicrosoft GraphDomain list for DKIM / SPF / DMARC checks
RoleManagement.Read.DirectoryMicrosoft GraphAdmin role members (prioritizes admin mailboxes in the inbox-rule scan)

Plus the built-in Global Reader directory role (view-only), assigned in the wizard’s final step.

SharePoint & OneDrive (M365 Assessment – SharePoint) · read-only
Permissions
PermissionResourceWhy we need it
SharePointTenantSettings.Read.AllMicrosoft GraphTenant sharing settings
Sites.Read.AllMicrosoft GraphSite inventory and group sites (read-only)
Reports.Read.AllMicrosoft GraphSharePoint site usage and OneDrive usage reports
ReportSettings.Read.AllMicrosoft GraphWhether usage reports conceal user names
GroupMember.Read.AllMicrosoft GraphMicrosoft 365 groups and their owners (group-connected sites)
Microsoft Teams (M365 Assessment – Teams) · read-only + Global Reader
Permissions
PermissionResourceWhy we need it
Organization.Read.AllMicrosoft GraphTenant lookup by Teams PowerShell app-only sign-in
TeamSettings.Read.AllMicrosoft GraphTeam settings (team inventory)
TeamworkDevice.Read.AllMicrosoft GraphTeams Rooms / phones and device health
GroupMember.Read.AllMicrosoft GraphMember / owner / guest counts per team
Channel.ReadBasic.AllMicrosoft GraphChannel counts per team (names only, never messages)

Plus the built-in Global Reader directory role (view-only).

Power Platform (opt-in) · NOT read-only
Permissions
PermissionResourceWhy we need it
Organization.Read.AllMicrosoft GraphTenant identity check before Power Platform collection

Plus registration as a Power Platform management application in the wizard’s final step. Microsoft gives management applications Power Platform administrator-level API access and offers no read-only option; M365Assessments only sends read (GET) requests.

SharePoint Advanced (opt-in) · NOT read-only
Permissions
PermissionResourceWhy we need it
Sites.FullControl.AllOffice 365 SharePoint OnlineWrite-capable: full control of all site collections. Required by Microsoft for the SharePoint tenant admin settings API. M365Assessments only issues read calls with it

The onboarding app (delegated only)

M365 Assessment – Onboarding is used only in the wizard's final step, in the administrator's own browser. It has no application permissions, no secret and no certificate, and acts only as the signed-in administrator while they're signed in:

  • openid, profile, User.Read: sign-in.
  • RoleManagement.ReadWrite.Directory: create the Global Reader assignment as the signed-in admin.
  • Application.Read.All: find the module apps in the tenant.
  • PowerApps Service User: register the Power Platform module app (requested only when that module is selected).

Signing in to the portal

Signing in to M365Assessments itself asks only for your basic profile: openid, profile, email and User.Read.

Good to know

Tenants connected before modules existed use one read-only app, M365Assessments Collector, until they upgrade (Legacy tenants).

What we never request

  • Any ReadWrite permission or write directory role in the read-only modules.
  • Access to email, files, chats, calendars or document contents.
  • Global Administrator. The engine warns if a module app holds it; it is never needed.

Last updated

Can't find what you need?

Our team is happy to help. Missing an article? Suggest it on the Feedback board in the app and vote for the ones you want.