Skip to content

Microsoft Permissions

Maintained by: Aether365 Team Audience: Microsoft 365 Global Administrators and security teams Scope: Full list of Microsoft Graph permissions requested by Aether365

When you connect a Microsoft 365 tenant to Aether365, your Global Administrator approves a set of read-only permissions on the Microsoft consent screen. This page lists every permission, its type, and why it is needed.

The permissions on this page are the read-only permissions used for scanning, and they are the default for every connected tenant. Aether365 also offers an optional, opt-in capability called AI Pilot, which adds a separate set of write permissions through a second consent so it can apply fixes you approve. AI Pilot write permissions are only granted if you explicitly enable AI Pilot for a tenant; otherwise the connection stays read-only.

Key Points

  • The scan permissions are application-level (not delegated to a user). The only delegated permission is User.Read, used solely to sign you in
  • The scan permissions are read-only - scanning cannot create, modify, or delete any data in your tenant
  • Write access is never granted by scanning. It is added only if you opt in to AI Pilot, through a separate consent, and is used solely to apply fixes you approve per item
  • Permissions are granted once via Global Admin consent and persist until you disconnect the tenant or delete the Aether365 service principal from your tenant
  • You can review and revoke permissions at any time from Microsoft Entra admin center > Enterprise Applications > Aether365

Permission Reference

PermissionTypeWhy it is needed
AccessReview.Read.AllApplicationRead access review definitions and results for governance checks
AppCatalog.Read.AllApplicationRead enterprise app catalog entries and approval policies
Application.Read.AllApplicationRead application registrations and credential configurations
AuditLog.Read.AllApplicationRead audit and sign-in logs required for EIDSCA and CISA benchmark checks
ChannelMember.Read.AllApplicationRead Teams channel membership to assess external and guest access
ChannelSettings.Read.AllApplicationRead Teams channel names, descriptions, and settings for collaboration controls
DeviceManagementConfiguration.Read.AllApplicationRead Intune device configuration and compliance policies
DeviceManagementManagedDevices.Read.AllApplicationRead managed device inventory and compliance state
DeviceManagementRBAC.Read.AllApplicationRead Intune RBAC role assignments
DeviceManagementServiceConfig.Read.AllApplicationRead Intune service configuration and enrollment settings
Directory.Read.AllApplicationRead users, groups, service principals, and directory objects to assess identity configuration
DirectoryRecommendations.Read.AllApplicationRead Entra ID recommendations for security posture improvements
Group.Read.AllApplicationRead group configurations and settings to assess access boundaries
GroupMember.Read.AllApplicationRead group membership to assess role and permission inheritance
IdentityRiskEvent.Read.AllApplicationRead risk event detections from Microsoft Entra ID Protection
MailboxConfigItem.ReadApplicationRead mailbox configuration objects for Exchange Online security checks
MailboxSettings.ReadApplicationRead Exchange Online mailbox settings and inbox rules for CIS email security controls
OnPremDirectorySynchronization.Read.AllApplicationRead on-premises directory synchronization configuration
Organization.Read.AllApplicationRead tenant-level configuration, license assignments, and organisation profile
Policy.Read.AllApplicationRead conditional access policies, authentication strength policies, and other security policies
Policy.Read.ConditionalAccessApplicationRead conditional access policy details for misconfiguration checks
PrivilegedAccess.Read.AzureADApplicationRead PIM role eligibility and activation settings
PrivilegedAccess.Read.AzureADGroupApplicationRead PIM group access eligibility settings
PrivilegedEligibilitySchedule.Read.AzureADGroupApplicationRead PIM group eligibility schedules
Reports.Read.AllApplicationRead usage reports and sign-in activity required by CIS and CISA benchmark checks
ReportSettings.Read.AllApplicationRead admin report display settings for accurate reporting
RoleManagement.Read.AllApplicationRead Entra ID role assignments to detect over-privileged accounts
RoleManagement.Read.DirectoryApplicationRead Entra ID directory role assignments and definitions
RoleManagementPolicy.Read.AzureADGroupApplicationRead PIM policies applied to group role assignments
SecurityEvents.Read.AllApplicationRead security alerts and events for threat exposure assessment
SecurityIdentitiesHealth.Read.AllApplicationRead Defender for Identity posture health issues
SecurityIdentitiesSensors.Read.AllApplicationRead Defender for Identity sensor configuration and health
SharePointTenantSettings.Read.AllApplicationRead SharePoint and OneDrive tenant-wide sharing and security settings
TeamSettings.Read.AllApplicationRead Teams team settings to assess external access and guest controls
ThreatHunting.Read.AllApplicationRun advanced hunting queries for threat exposure assessment
User.Read.AllApplicationRead user profiles, sign-in settings, and license assignments
UserAuthenticationMethod.Read.AllApplicationRead registered MFA methods to verify per-user authentication strength
User.ReadDelegatedSign in and read the signed-in user's basic profile

Reviewing Granted Permissions

To verify which permissions Aether365 has in your tenant:

  1. Sign in to the Microsoft Entra admin center
  2. Navigate to Enterprise Applications
  3. Search for "Aether365"
  4. Select the application and open Permissions

The permissions page shows all consented permissions along with who granted consent and when.

Revoking Permissions

To revoke all Aether365 permissions from a tenant:

  1. In Microsoft Entra admin center > Enterprise Applications, select Aether365
  2. Click Delete to remove the service principal entirely

This revokes all permissions and stops Aether365 from accessing the tenant. Future scan attempts for this tenant will fail. To stop scans, also disconnect the tenant in the Aether365 dashboard (Settings > Connections).

Questions

If you have questions about a specific permission or need to discuss permission scope for an Enterprise deployment, contact security@aether365.io.

Was this page helpful?