Microsoft Graph permissions
This is the full list of what TrueConfig asks Microsoft for. They are delegated permissions: a Microsoft 365 administrator approves them on Microsoft's own consent screen, and you can remove them at any time by deleting TrueConfig from Enterprise applications in Entra.
1. Connect and scan: read only
Connecting a tenant and running scans requests only the read permissions below. No write permission is part of this step, so TrueConfig cannot change anything in your tenant after it.
| Permission | Access | Why we need it |
|---|---|---|
| User.Read.All | Read | List users and their properties (account status, user type, admin and guest accounts). |
| Policy.Read.All | Read | Read Conditional Access, authentication methods, authorization and cross-tenant policies to compare them with your baseline. |
| Application.Read.All | Read | Read app registrations and enterprise applications, including their permissions and credential expiry. |
| RoleManagement.Read.Directory | Read | Read directory role assignments, for example how many Global Administrators you have. |
| Group.Read.All | Read | Read groups and their members, for controls about privileged and guest group membership. |
| AuditLog.Read.All | Read | Read sign-in and directory audit logs for controls about guest activity and logging. |
| UserAuthenticationMethod.Read.All | Read | Read which authentication methods each user has registered, to see who has MFA. |
| Reports.Read.All | Read | Read the MFA registration report. |
| Organization.Read.All | Read | Read the tenant name and verified domains so we can show which tenant you connected. |
Sign-in scopes (identity, not tenant data)
- openid, profile, email: Identify the Microsoft account that approved the connection.
- offline_access: Keep a refresh token so scheduled scans can run without you signing in each time.
2. Fixes: write, separate consent
If you want TrueConfig to apply a fix for you, you are asked to consent again. Nothing here is requested during the read-only connect step. These are the core write permissions:
| Permission | Access | Why we need it |
|---|---|---|
| User.ReadWrite.All | Write | Change a user setting when a fix needs it. |
| RoleManagement.ReadWrite.Directory | Write | Remove excess directory role assignments. |
| Policy.ReadWrite.ConditionalAccess | Write | Create or update Conditional Access policies. |
| Policy.ReadWrite.AuthenticationMethod | Write | Change the authentication methods policy (for example passwordless settings). |
| Policy.ReadWrite.Authorization | Write | Change tenant authorization settings such as guest access. |
| Policy.ReadWrite.CrossTenantAccess | Write | Change cross-tenant access settings. |
The fix consent also adds two read permissions so a fix can check its target first:
| Permission | Access | Why we need it |
|---|---|---|
| Directory.Read.All | Read | Read directory objects so a fix can check its target before changing it. |
| RoleManagement.Read.All | Read | Read role management data before a role-related fix. |
3. Optional fix capabilities
These higher-impact write permissions are never part of the default fix consent. They are requested only if you choose that capability.
Manage application permissions
Disable risky service principals and revoke app role / delegated permission grants. Includes AppRoleAssignment.ReadWrite.All, a high-privilege scope that can grant apps any permission - only enable if you want automated app-permission fixes.
Application.ReadWrite.All, AppRoleAssignment.ReadWrite.All, DelegatedPermissionGrant.ReadWrite.All
Remove mailbox forwarding rules
Delete auto-forwarding inbox rules flagged by EXT-07 (Mail.ReadWrite).
Mail.ReadWrite
Configure admin consent workflow
Enable the admin consent request workflow for APP-04 (Policy.ReadWrite.ConsentRequest).
Policy.ReadWrite.ConsentRequest
Create guest access reviews
Create access-review definitions for guest lifecycle (EXT-04, AccessReview.ReadWrite.All).
AccessReview.ReadWrite.All
What we do with the data
Scan results (settings, policy definitions, role and group membership, MFA registration status) are stored in the EU and are separated per organization. Microsoft OAuth tokens are encrypted before they are saved. See the Privacy Policy for retention and processors, and Security for our compliance status.
Questions about a specific permission: security@trueconfig.io.