Microsoft Permissions
Maintained by: Aether365 Team Audience: Microsoft 365 Global Administrators and security teams Scope: Full list of Microsoft Graph permissions requested by Aether365
When you connect a Microsoft 365 tenant to Aether365, your Global Administrator approves a set of read-only permissions on the Microsoft consent screen. This page lists every permission, its type, and why it is needed.
The permissions on this page are the read-only permissions used for scanning, and they are the default for every connected tenant. Aether365 also offers an optional, opt-in capability called AI Pilot, which adds a separate set of write permissions through a second consent so it can apply fixes you approve. AI Pilot write permissions are only granted if you explicitly enable AI Pilot for a tenant; otherwise the connection stays read-only.
Key Points
- The scan permissions are application-level (not delegated to a user). The only delegated permission is
User.Read, used solely to sign you in - The scan permissions are read-only - scanning cannot create, modify, or delete any data in your tenant
- Write access is never granted by scanning. It is added only if you opt in to AI Pilot, through a separate consent, and is used solely to apply fixes you approve per item
- Permissions are granted once via Global Admin consent and persist until you disconnect the tenant or delete the Aether365 service principal from your tenant
- You can review and revoke permissions at any time from Microsoft Entra admin center > Enterprise Applications > Aether365
Permission Reference
| Permission | Type | Why it is needed |
|---|---|---|
AccessReview.Read.All | Application | Read access review definitions and results for governance checks |
AppCatalog.Read.All | Application | Read enterprise app catalog entries and approval policies |
Application.Read.All | Application | Read application registrations and credential configurations |
AuditLog.Read.All | Application | Read audit and sign-in logs required for EIDSCA and CISA benchmark checks |
ChannelMember.Read.All | Application | Read Teams channel membership to assess external and guest access |
ChannelSettings.Read.All | Application | Read Teams channel names, descriptions, and settings for collaboration controls |
DeviceManagementConfiguration.Read.All | Application | Read Intune device configuration and compliance policies |
DeviceManagementManagedDevices.Read.All | Application | Read managed device inventory and compliance state |
DeviceManagementRBAC.Read.All | Application | Read Intune RBAC role assignments |
DeviceManagementServiceConfig.Read.All | Application | Read Intune service configuration and enrollment settings |
Directory.Read.All | Application | Read users, groups, service principals, and directory objects to assess identity configuration |
DirectoryRecommendations.Read.All | Application | Read Entra ID recommendations for security posture improvements |
Group.Read.All | Application | Read group configurations and settings to assess access boundaries |
GroupMember.Read.All | Application | Read group membership to assess role and permission inheritance |
IdentityRiskEvent.Read.All | Application | Read risk event detections from Microsoft Entra ID Protection |
MailboxConfigItem.Read | Application | Read mailbox configuration objects for Exchange Online security checks |
MailboxSettings.Read | Application | Read Exchange Online mailbox settings and inbox rules for CIS email security controls |
OnPremDirectorySynchronization.Read.All | Application | Read on-premises directory synchronization configuration |
Organization.Read.All | Application | Read tenant-level configuration, license assignments, and organisation profile |
Policy.Read.All | Application | Read conditional access policies, authentication strength policies, and other security policies |
Policy.Read.ConditionalAccess | Application | Read conditional access policy details for misconfiguration checks |
PrivilegedAccess.Read.AzureAD | Application | Read PIM role eligibility and activation settings |
PrivilegedAccess.Read.AzureADGroup | Application | Read PIM group access eligibility settings |
PrivilegedEligibilitySchedule.Read.AzureADGroup | Application | Read PIM group eligibility schedules |
Reports.Read.All | Application | Read usage reports and sign-in activity required by CIS and CISA benchmark checks |
ReportSettings.Read.All | Application | Read admin report display settings for accurate reporting |
RoleManagement.Read.All | Application | Read Entra ID role assignments to detect over-privileged accounts |
RoleManagement.Read.Directory | Application | Read Entra ID directory role assignments and definitions |
RoleManagementPolicy.Read.AzureADGroup | Application | Read PIM policies applied to group role assignments |
SecurityEvents.Read.All | Application | Read security alerts and events for threat exposure assessment |
SecurityIdentitiesHealth.Read.All | Application | Read Defender for Identity posture health issues |
SecurityIdentitiesSensors.Read.All | Application | Read Defender for Identity sensor configuration and health |
SharePointTenantSettings.Read.All | Application | Read SharePoint and OneDrive tenant-wide sharing and security settings |
TeamSettings.Read.All | Application | Read Teams team settings to assess external access and guest controls |
ThreatHunting.Read.All | Application | Run advanced hunting queries for threat exposure assessment |
User.Read.All | Application | Read user profiles, sign-in settings, and license assignments |
UserAuthenticationMethod.Read.All | Application | Read registered MFA methods to verify per-user authentication strength |
User.Read | Delegated | Sign in and read the signed-in user's basic profile |
Reviewing Granted Permissions
To verify which permissions Aether365 has in your tenant:
- Sign in to the Microsoft Entra admin center
- Navigate to Enterprise Applications
- Search for "Aether365"
- Select the application and open Permissions
The permissions page shows all consented permissions along with who granted consent and when.
Revoking Permissions
To revoke all Aether365 permissions from a tenant:
- In Microsoft Entra admin center > Enterprise Applications, select Aether365
- Click Delete to remove the service principal entirely
This revokes all permissions and stops Aether365 from accessing the tenant. Future scan attempts for this tenant will fail. To stop scans, also disconnect the tenant in the Aether365 dashboard (Settings > Connections).
Questions
If you have questions about a specific permission or need to discuss permission scope for an Enterprise deployment, contact security@aether365.io.