| Core module (always required): identity & tenant core (Microsoft Entra ID) |
| 1 | Directory.Read.All | Users, groups, roles, applications and other directory objects that most checks build on. |
| 2 | Organization.Read.All | Tenant profile, verified domains and subscriptions. |
| 3 | AuditLog.Read.All | Sign-in activity: legacy-authentication usage, stale accounts and last sign-in dates. |
| 4 | SecurityEvents.Read.All | Microsoft Secure Score and its control profiles. |
| 5 | Policy.Read.All | Conditional Access, authentication methods, authorization and cross-tenant access policies. |
| 6 | RoleManagement.Read.Directory | Admin role assignments and Privileged Identity Management (PIM) eligibility. |
| 7 | IdentityRiskyUser.Read.All | Users flagged as risky by Microsoft Entra ID Protection. |
| 8 | IdentityRiskEvent.Read.All | Risk detections, including risky sign-ins. |
| 9 | IdentityRiskyServicePrincipal.Read.All | Risky workload identities (service principals) and their detections. |
| 10 | Agreement.Read.All | Terms of use agreements. |
| 11 | AccessReview.Read.All | Access review definitions. |
| 12 | DirectoryRecommendations.Read.All | Microsoft Entra recommendations for the tenant. |
| 13 | OnPremDirectorySynchronization.Read.All | Microsoft Entra Connect (directory sync) configuration. |
| 14 | CrossTenantInformation.ReadBasic.All | Resolving partner tenant names in cross-tenant access settings. |
| 15 | Synchronization.Read.All | Provisioning (SCIM) jobs on enterprise applications. |
| Devices (Microsoft Intune) |
| 16 | DeviceManagementManagedDevices.Read.All | Managed device inventory, compliance state and device clean-up rules. |
| 17 | DeviceManagementConfiguration.Read.All | Compliance and configuration profiles, settings catalog, endpoint security and update rings. |
| 18 | DeviceManagementApps.Read.All | Managed apps and iOS/Android app protection policies. |
| 19 | DeviceManagementServiceConfig.Read.All | Windows Autopilot devices and profiles, enrollment and connector configuration. |
| 20 | DeviceManagementRBAC.Read.All | Intune role settings, including multi-admin approval. |
| 21 | DeviceManagementScripts.Read.All | Platform scripts and remediations. |
| Licensing & usage |
| 22 | Reports.Read.All | Microsoft 365 active-user and usage reports, including Microsoft 365 Copilot usage. |
| 23 | ReportSettings.Read.All | Whether the tenant conceals user names in usage reports. |