Skip to content
365Posture

Permissions disclosure

365Posture collector scripts request read-only Microsoft Graph API permissions only. No write permissions are ever requested. You can verify every one of these on the Entra admin consent screen before granting access. Permissions are granted to an app registration you create, in your own tenant — 365Posture never stores your credentials.

Entra ID Assessment

31 controls — Identity, MFA, Conditional Access, privileged roles, and legacy authentication.

Permission Why it's needed
Directory.Read.All READ Read directory roles, members, and group information to check admin count and privileged access
Policy.Read.All READ Read Conditional Access policies, security defaults, external collaboration settings, and SSPR configuration
User.Read.All READ Read user accounts to identify guest users and check account states
AuditLog.Read.All READ Read MFA registration details and sign-in logs to detect legacy authentication
Reports.Read.All READ Read authentication method usage reports
IdentityRiskEvent.Read.All READ Read risky sign-in events and user risk levels (requires Entra ID P2)

Exchange Online Assessment

18 controls — Anti-phishing, DKIM, transport rules, auto-forwarding, and mail flow hardening.

Permission Why it's needed
Directory.Read.All READ Read tenant and domain information
Policy.Read.All READ Read organisation-wide policy settings
User.Read.All READ Read user account information
AuditLog.Read.All READ Read audit log configuration
Reports.Read.All READ Read Exchange usage and configuration reports
Exchange.ManageAsApp READ App-only access to Exchange Online PowerShell for reading anti-phishing, DKIM, transport, and mail flow settings (no mailbox access)
Note: Exchange.ManageAsApp grants app-only access to Exchange Online management APIs — not to individual mailboxes or mail content. The app is assigned to the View-Only Organization Management role group only.

Microsoft Intune Assessment

18 controls — Device compliance, configuration profiles, BitLocker, app protection, and RBAC.

Permission Why it's needed
Directory.Read.All READ Read tenant and subscription information
Policy.Read.All READ Read Intune compliance and configuration policies
User.Read.All READ Read user account and device assignment information
DeviceManagementConfiguration.Read.All READ Read device configuration profiles and compliance policies
DeviceManagementManagedDevices.Read.All READ Read managed device inventory and compliance state
DeviceManagementApps.Read.All READ Read app protection (MAM) policies and app configuration
DeviceManagementRBAC.Read.All READ Read Intune RBAC role definitions
DeviceManagementServiceConfig.Read.All READ Read enrollment configurations and Terms & Conditions

Microsoft Purview Assessment

16 controls — Sensitivity labels, DLP, retention policies, communication compliance, and eDiscovery.

Permission Why it's needed
Directory.Read.All READ Read tenant and subscription information
Policy.Read.All READ Read information protection policies
User.Read.All READ Read user account information
AuditLog.Read.All READ Read audit logging configuration and status
InformationProtectionPolicy.Read.All READ Read sensitivity labels and label policies
eDiscovery.Read.All READ Read eDiscovery case inventory and status

SharePoint Online Assessment

16 controls — External sharing, anonymous links, sync client restrictions, and Conditional Access.

Permission Why it's needed
Directory.Read.All READ Read tenant and Microsoft 365 group information
Policy.Read.All READ Read Conditional Access policies applied to SharePoint
User.Read.All READ Read user account information
Sites.Read.All READ Read SharePoint site collection configuration and sharing settings
Files.Read.All READ Read SharePoint and OneDrive sharing configuration

Microsoft Teams Assessment

15 controls — External access, guest settings, meeting policies, app permissions, and sideloading.

Permission Why it's needed
Directory.Read.All READ Read tenant information
Policy.Read.All READ Read Teams meeting and messaging policies
User.Read.All READ Read user account information
TeamSettings.Read.All READ Read Teams organisation-wide settings, external access configuration, app permission policies, and meeting policies

Defender for M365 Assessment

18 controls — Secure Score, MDE deployment, tamper protection, attack simulation, and Safe Attachments/Links.

Permission Why it's needed
Directory.Read.All READ Read tenant information
Policy.Read.All READ Read Conditional Access and security policies
User.Read.All READ Read user account information
DeviceManagementManagedDevices.Read.All READ Read managed device list and MDE onboarding state
SecurityEvents.Read.All READ Read security alerts and incidents
SecurityIncident.Read.All READ Read security incident details
SecurityAlert.Read.All READ Read high/critical security alerts
AttackSimulation.Read.All READ Read Attack Simulator campaign results

All permissions listed above are application permissions (app-only, no user delegation).