Microsoft Graph permissions

This is the full list of what TrueConfig asks Microsoft for. They are delegated permissions: a Microsoft 365 administrator approves them on Microsoft's own consent screen, and you can remove them at any time by deleting TrueConfig from Enterprise applications in Entra.

1. Connect and scan: read only

Connecting a tenant and running scans requests only the read permissions below. No write permission is part of this step, so TrueConfig cannot change anything in your tenant after it.

PermissionAccessWhy we need it
User.Read.All
Read
List users and their properties (account status, user type, admin and guest accounts).
Policy.Read.All
Read
Read Conditional Access, authentication methods, authorization and cross-tenant policies to compare them with your baseline.
Application.Read.All
Read
Read app registrations and enterprise applications, including their permissions and credential expiry.
RoleManagement.Read.Directory
Read
Read directory role assignments, for example how many Global Administrators you have.
Group.Read.All
Read
Read groups and their members, for controls about privileged and guest group membership.
AuditLog.Read.All
Read
Read sign-in and directory audit logs for controls about guest activity and logging.
UserAuthenticationMethod.Read.All
Read
Read which authentication methods each user has registered, to see who has MFA.
Reports.Read.All
Read
Read the MFA registration report.
Organization.Read.All
Read
Read the tenant name and verified domains so we can show which tenant you connected.

Sign-in scopes (identity, not tenant data)

  • openid, profile, email: Identify the Microsoft account that approved the connection.
  • offline_access: Keep a refresh token so scheduled scans can run without you signing in each time.

2. Fixes: write, separate consent

If you want TrueConfig to apply a fix for you, you are asked to consent again. Nothing here is requested during the read-only connect step. These are the core write permissions:

PermissionAccessWhy we need it
User.ReadWrite.All
Write
Change a user setting when a fix needs it.
RoleManagement.ReadWrite.Directory
Write
Remove excess directory role assignments.
Policy.ReadWrite.ConditionalAccess
Write
Create or update Conditional Access policies.
Policy.ReadWrite.AuthenticationMethod
Write
Change the authentication methods policy (for example passwordless settings).
Policy.ReadWrite.Authorization
Write
Change tenant authorization settings such as guest access.
Policy.ReadWrite.CrossTenantAccess
Write
Change cross-tenant access settings.

The fix consent also adds two read permissions so a fix can check its target first:

PermissionAccessWhy we need it
Directory.Read.All
Read
Read directory objects so a fix can check its target before changing it.
RoleManagement.Read.All
Read
Read role management data before a role-related fix.

3. Optional fix capabilities

These higher-impact write permissions are never part of the default fix consent. They are requested only if you choose that capability.

Manage application permissions

high impact

Disable risky service principals and revoke app role / delegated permission grants. Includes AppRoleAssignment.ReadWrite.All, a high-privilege scope that can grant apps any permission - only enable if you want automated app-permission fixes.

Application.ReadWrite.All, AppRoleAssignment.ReadWrite.All, DelegatedPermissionGrant.ReadWrite.All

Remove mailbox forwarding rules

medium impact

Delete auto-forwarding inbox rules flagged by EXT-07 (Mail.ReadWrite).

Mail.ReadWrite

Configure admin consent workflow

low impact

Enable the admin consent request workflow for APP-04 (Policy.ReadWrite.ConsentRequest).

Policy.ReadWrite.ConsentRequest

Create guest access reviews

low impact

Create access-review definitions for guest lifecycle (EXT-04, AccessReview.ReadWrite.All).

AccessReview.ReadWrite.All

What we do with the data

Scan results (settings, policy definitions, role and group membership, MFA registration status) are stored in the EU and are separated per organization. Microsoft OAuth tokens are encrypted before they are saved. See the Privacy Policy for retention and processors, and Security for our compliance status.

Questions about a specific permission: security@trueconfig.io.