Permissions disclosure
365Posture collector scripts request read-only Microsoft Graph API permissions only. No write permissions are ever requested. You can verify every one of these on the Entra admin consent screen before granting access. Permissions are granted to an app registration you create, in your own tenant — 365Posture never stores your credentials.
Entra ID Assessment
31 controls — Identity, MFA, Conditional Access, privileged roles, and legacy authentication.
| Permission | Why it's needed |
|---|---|
| Directory.Read.All READ | Read directory roles, members, and group information to check admin count and privileged access |
| Policy.Read.All READ | Read Conditional Access policies, security defaults, external collaboration settings, and SSPR configuration |
| User.Read.All READ | Read user accounts to identify guest users and check account states |
| AuditLog.Read.All READ | Read MFA registration details and sign-in logs to detect legacy authentication |
| Reports.Read.All READ | Read authentication method usage reports |
| IdentityRiskEvent.Read.All READ | Read risky sign-in events and user risk levels (requires Entra ID P2) |
Exchange Online Assessment
18 controls — Anti-phishing, DKIM, transport rules, auto-forwarding, and mail flow hardening.
| Permission | Why it's needed |
|---|---|
| Directory.Read.All READ | Read tenant and domain information |
| Policy.Read.All READ | Read organisation-wide policy settings |
| User.Read.All READ | Read user account information |
| AuditLog.Read.All READ | Read audit log configuration |
| Reports.Read.All READ | Read Exchange usage and configuration reports |
| Exchange.ManageAsApp READ | App-only access to Exchange Online PowerShell for reading anti-phishing, DKIM, transport, and mail flow settings (no mailbox access) |
Microsoft Intune Assessment
18 controls — Device compliance, configuration profiles, BitLocker, app protection, and RBAC.
| Permission | Why it's needed |
|---|---|
| Directory.Read.All READ | Read tenant and subscription information |
| Policy.Read.All READ | Read Intune compliance and configuration policies |
| User.Read.All READ | Read user account and device assignment information |
| DeviceManagementConfiguration.Read.All READ | Read device configuration profiles and compliance policies |
| DeviceManagementManagedDevices.Read.All READ | Read managed device inventory and compliance state |
| DeviceManagementApps.Read.All READ | Read app protection (MAM) policies and app configuration |
| DeviceManagementRBAC.Read.All READ | Read Intune RBAC role definitions |
| DeviceManagementServiceConfig.Read.All READ | Read enrollment configurations and Terms & Conditions |
Microsoft Purview Assessment
16 controls — Sensitivity labels, DLP, retention policies, communication compliance, and eDiscovery.
| Permission | Why it's needed |
|---|---|
| Directory.Read.All READ | Read tenant and subscription information |
| Policy.Read.All READ | Read information protection policies |
| User.Read.All READ | Read user account information |
| AuditLog.Read.All READ | Read audit logging configuration and status |
| InformationProtectionPolicy.Read.All READ | Read sensitivity labels and label policies |
| eDiscovery.Read.All READ | Read eDiscovery case inventory and status |
SharePoint Online Assessment
16 controls — External sharing, anonymous links, sync client restrictions, and Conditional Access.
| Permission | Why it's needed |
|---|---|
| Directory.Read.All READ | Read tenant and Microsoft 365 group information |
| Policy.Read.All READ | Read Conditional Access policies applied to SharePoint |
| User.Read.All READ | Read user account information |
| Sites.Read.All READ | Read SharePoint site collection configuration and sharing settings |
| Files.Read.All READ | Read SharePoint and OneDrive sharing configuration |
Microsoft Teams Assessment
15 controls — External access, guest settings, meeting policies, app permissions, and sideloading.
| Permission | Why it's needed |
|---|---|
| Directory.Read.All READ | Read tenant information |
| Policy.Read.All READ | Read Teams meeting and messaging policies |
| User.Read.All READ | Read user account information |
| TeamSettings.Read.All READ | Read Teams organisation-wide settings, external access configuration, app permission policies, and meeting policies |
Defender for M365 Assessment
18 controls — Secure Score, MDE deployment, tamper protection, attack simulation, and Safe Attachments/Links.
| Permission | Why it's needed |
|---|---|
| Directory.Read.All READ | Read tenant information |
| Policy.Read.All READ | Read Conditional Access and security policies |
| User.Read.All READ | Read user account information |
| DeviceManagementManagedDevices.Read.All READ | Read managed device list and MDE onboarding state |
| SecurityEvents.Read.All READ | Read security alerts and incidents |
| SecurityIncident.Read.All READ | Read security incident details |
| SecurityAlert.Read.All READ | Read high/critical security alerts |
| AttackSimulation.Read.All READ | Read Attack Simulator campaign results |
All permissions listed above are application permissions (app-only, no user delegation).