Reference
Microsoft Permissions
The permissions Rencore Governance requests per authenticator, and the inventories that rely on each permission.
Auditing
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read activity feed | Allows to read activity feed. | Application | |
| Read all usage reports | Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Microsoft 365 and Microsoft Entra ID. | Application | Summary of active user (Report) , Trend of daily active user (Report) , Copilot user activity (Report) , User Activity , Usage , User Activity , Device Usage |
| Read audit log | Allows to read audit log. | Application | Risky Entra ID Sign-In , User Registration Credential |
| Read directory data | Allows the app to read data in your organization's directory, such as users, groups and apps, without a signed-in user. | Application | Registration Certificate , Client secret , Application registration , App Role Assignment , App Role , Deleted App Registration Certificate , Deleted App Client secret , Deleted Application Registration , Deleted Application Verified Publisher , Device , DeviceOwnerEntity , DeviceUserEntity , Directory Role , Domain , Enterprise Registration Certificate , Enterprise App Client secret , Enterprise Application Verified Publisher , Enterprise Application , Enterprise Application OAuth2 Permission Scope , EnterpriseApplicationOwnerEntity , OAuth2 Permission Grant , OAuth2 Permission Scope , Verified Publisher |
| Read service health | Allows the app to read service health information. | Application | |
| Read service messages | Allows the app to read your tenant's service announcement messages, without a signed-in user. Messages may include information about new or changed features. | Application | Message Center Message |
Entra ID
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read directory data | Allows the app to read data in your organization's directory, such as users, groups and apps, without a signed-in user. | Application | Registration Certificate , Client secret , Application registration , App Role Assignment , App Role , Deleted App Registration Certificate , Deleted App Client secret , Deleted Application Registration , Deleted Application Verified Publisher , Device , DeviceOwnerEntity , DeviceUserEntity , Directory Role , Domain , Enterprise Registration Certificate , Enterprise App Client secret , Enterprise Application Verified Publisher , Enterprise Application , Enterprise Application OAuth2 Permission Scope , EnterpriseApplicationOwnerEntity , OAuth2 Permission Grant , OAuth2 Permission Scope , Verified Publisher |
Azure
| Permission | Description | Type | Used by |
|---|---|---|---|
| Access the Azure API | Accesses all routes in the Azure API. | Application | Advisor Recommendation , Resource Group , AzureResourceGroupOwnerEntity , Subscription , Virtual Machine , Web App , AI Agent , LLM Deployment , Finetune Job , AI Hub , AI Project , AI Service , Daily Costs |
Copilot
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all Copilot agent and app packages | Allows the app to read all agents and apps from the tenant agent registry without a signed-in user. | Application | Agent Builder Action , CopilotAgentBuilderPackageActionLinkEntity , Agent Builder Capability , CopilotAgentBuilderPackageCapabilityLinkEntity , Agent Builder Element , Agent Builder Agent , Agent Builder Knowledge Source , CopilotAgentBuilderPackageKnowledgeSourceLinkEntity , Agent365AgentPackageActionEntity , Agent365AgentPackageActionLinkEntity , Agent365AgentPackageCapabilityEntity , Agent365AgentPackageCapabilityLinkEntity , Agent365AgentPackageElementEntity , Agent365AgentPackageEntity , Agent365AgentPackageKnowledgeSourceEntity , Agent365AgentPackageKnowledgeSourceLinkEntity |
| Read all external connections | Allows the app to read all external connections without a signed-in user. | Application | External Graph Connection |
| Read all usage reports | Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Microsoft 365 and Microsoft Entra ID. | Application | Summary of active user (Report) , Trend of daily active user (Report) , Copilot user activity (Report) , User Activity , Usage , User Activity , Device Usage |
| Read audit logs data from all services | Allows the app to read and query audit logs from all services. | Application | |
| Read user AI enterprise interactions | Allows the app to read all AI enterprise interactions. | Application | M365 Copilot session |
Dataverse
| Permission | Description | Type | Used by |
|---|---|---|---|
| Access the Dataverse Service API | Access Common Data Service as organization users. | Application | Environment , DataverseEnvironmentEntity |
| Access the Power Platform admin API | Access environment management, tenant settings, and Power Apps management. | Application | Pay-as-you-go Plan , Tenant Settings |
| Dataverse Permission prvReadAICopilot | Access Common Data Service as organization users. | Application | Microsoft Copilot |
| Dataverse Permission prvReadOrganization | Access Common Data Service as organization users. | Application | Power Pages Site , Power Platform Solution |
| Dataverse Permission prvReadWorkflow | Access Common Data Service as organization users. | Application | Agent Flow |
| Dataverse Permission prvReadbot | Access Common Data Service as organization users. | Application | Copilot Agent , CustomCopilotMemberEntity |
| Dataverse Permission prvReadbotcomponent | Access Common Data Service as organization users. | Application | Action , Knowledge , Topic , Trigger |
| Dataverse Permission prvReadconversationtranscript | Access Common Data Service as organization users. | Application | Agent Conversation |
Exchange Admin
| Permission | Description | Type | Used by |
|---|---|---|---|
| Manage Exchange As Application | Allows the app to call Exchange Online cmdlets via the Admin REST API. Requires an additional Exchange RBAC role assignment in the customer tenant. | Application | Accepted Domain , Distribution Group , Exchange Organization Configuration , Exchange Role Assignment , Exchange Role Group , ExchangeRoleGroupManagerEntity , ExchangeRoleGroupMemberEntity , Exchange Security Policy , Journal Rule , Mail Contact , Mail Flow Connector , Mail User , Mailbox Audit Bypass , Mailbox Delegate , Mailbox Folder Permission , Mobile Device , Mobile Device Policy , Remote Domain , Resource Mailbox , Transport Rule |
Exchange
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all usage reports | Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Microsoft 365 and Microsoft Entra ID. | Application | Summary of active user (Report) , Trend of daily active user (Report) , Copilot user activity (Report) , User Activity , Usage , User Activity , Device Usage |
| Read calendars in all mailboxes | Allows the app to read events of all calendars without a signed-in user. | Application | Calendar Permission |
| Read user mailbox settings | Allows the app to the read user's mailbox settings. Does not include permission to send mail. | Application | Redirect Rule , Mailbox |
Microsoft 365 All services
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read activity feed | Allows to read activity feed. | Application | |
| Read all Copilot agent and app packages | Allows the app to read all agents and apps from the tenant agent registry without a signed-in user. | Application | Agent Builder Action , CopilotAgentBuilderPackageActionLinkEntity , Agent Builder Capability , CopilotAgentBuilderPackageCapabilityLinkEntity , Agent Builder Element , Agent Builder Agent , Agent Builder Knowledge Source , CopilotAgentBuilderPackageKnowledgeSourceLinkEntity , Agent365AgentPackageActionEntity , Agent365AgentPackageActionLinkEntity , Agent365AgentPackageCapabilityEntity , Agent365AgentPackageCapabilityLinkEntity , Agent365AgentPackageElementEntity , Agent365AgentPackageEntity , Agent365AgentPackageKnowledgeSourceEntity , Agent365AgentPackageKnowledgeSourceLinkEntity |
| Read all Viva Engage communities | Allows the app to list Viva Engage communities, and to read their properties on behalf of the signed-in user. | Application | VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community |
| Read all app catalogs | Allows the app to read the apps in the app catalogs. | Application | App |
| Read all channel messages | Allows the app to read all channel messages in Microsoft Teams, without a signed-in user. | Application | |
| Read all company places | Allows the app to read company places (conference rooms and room lists) for calendar events and other applications. | Application | Rooms & Equipment |
| Read all groups | Allows the app to read memberships for all groups without a signed-in user. Also allows the app to read calendar, conversations, files, and other group content for all groups. | Application | Deleted Group , Group , GroupMemberEntity , GroupOwnerEntity , GroupToGroupRelationEntity , Deleted Team , Channel , TeamsChannelMemberEntity , Team , TeamsInstalledAppRelationEntity , TeamsMemberEntity , TeamsOwnerEntity , Tab , VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community |
| Read all published labels and label policies for an organization | Allows an app to read published sensitivity labels and label policy settings for the entire organization or a specific user, without a signed in user. | Application | Sensitivity Label |
| Read all usage reports | Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Microsoft 365 and Microsoft Entra ID. | Application | Summary of active user (Report) , Trend of daily active user (Report) , Copilot user activity (Report) , User Activity , Usage , User Activity , Device Usage |
| Read all users' full profiles | Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user. | Application | Agent365AgentUserEntity , Deleted User , User , TeamsMemberEntity , TeamsOwnerEntity |
| Read all users' tasks and tasklist | Allows the app to read all users' tasks and task lists in your organization, without a signed-in user. | Application | Plan , PlannerPlanMemberEntity , PlannerPlanOwnerEntity |
| Read audit log | Allows to read audit log. | Application | Risky Entra ID Sign-In , User Registration Credential |
| Read directory data | Allows the app to read data in your organization's directory, such as users, groups and apps, without a signed-in user. | Application | Registration Certificate , Client secret , Application registration , App Role Assignment , App Role , Deleted App Registration Certificate , Deleted App Client secret , Deleted Application Registration , Deleted Application Verified Publisher , Device , DeviceOwnerEntity , DeviceUserEntity , Directory Role , Domain , Enterprise Registration Certificate , Enterprise App Client secret , Enterprise Application Verified Publisher , Enterprise Application , Enterprise Application OAuth2 Permission Scope , EnterpriseApplicationOwnerEntity , OAuth2 Permission Grant , OAuth2 Permission Scope , Verified Publisher |
| Read file data | Allows the app to read data in your organization's file. | Application | OneDrive |
| Read items in all site collections | Allows the app to read documents and list items in all site collections without a signed in user. | Application | GroupSiteCollectionEntity , SharePoint Agent , Deleted Site Collection , List/Library , Locked Site Collection , Site Collection , SharePoint Special Group , Site , TeamsSharePointSiteEntity |
| Read organization information | Allows the app to read the organization and related resources, without a signed-in user. Related resources include things like subscribed SKUs and tenant branding information. | Application | Subscription , Service Assignment , App , UserLicenseEntity , UserServicePlanEntity |
| Read service health | Allows the app to read service health information. | Application | |
| Read service messages | Allows the app to read your tenant's service announcement messages, without a signed-in user. Messages may include information about new or changed features. | Application | Message Center Message |
| Read teams' settings | Read this team's settings, on behalf of the signed-in user. | Application | |
| Read the members of all channels. | Read the members of all channels, without a signed-in user. | Application | Shared Channel External Member , TeamsSharedChannelRelationEntity |
| Read the members of all teams. | Read the members of all teams, without a signed-in user. | Application | |
| Read user mailbox settings | Allows the app to the read user's mailbox settings. Does not include permission to send mail. | Application | Redirect Rule , Mailbox |
Microsoft 365
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all company places | Allows the app to read company places (conference rooms and room lists) for calendar events and other applications. | Application | Rooms & Equipment |
| Read all groups | Allows the app to read memberships for all groups without a signed-in user. Also allows the app to read calendar, conversations, files, and other group content for all groups. | Application | Deleted Group , Group , GroupMemberEntity , GroupOwnerEntity , GroupToGroupRelationEntity , Deleted Team , Channel , TeamsChannelMemberEntity , Team , TeamsInstalledAppRelationEntity , TeamsMemberEntity , TeamsOwnerEntity , Tab , VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community |
| Read all users' full profiles | Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user. | Application | Agent365AgentUserEntity , Deleted User , User , TeamsMemberEntity , TeamsOwnerEntity |
| Read domains | Allows the app to read all domain properties without a signed-in user. | Application | Domain |
| Read organization information | Allows the app to read the organization and related resources, without a signed-in user. Related resources include things like subscribed SKUs and tenant branding information. | Application | Subscription , Service Assignment , App , UserLicenseEntity , UserServicePlanEntity |
| Read role management data for Entra ID | Allows the app to read the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes reading directory role templates, directory roles and memberships. | Application | Directory Role |
Intune
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read Conditional Access Policies | View all conditional access policies and device trust configurations | Application | IntuneConditionalAccessPolicyEntity |
| Read Intune Audit Events | View Intune device management audit events and action history | Application | IntuneAuditEventEntity |
| Read Intune Configuration | View all Intune device configurations and compliance policies | Application | IntuneCompliancePolicyEntity , IntuneDeviceCategoryEntity , IntuneDeviceConfigurationEntity , IntuneDeviceConfigurationStateEntity , IntuneDeviceScriptEntity , IntuneSecurityBaselineDeviceStateEntity , IntuneSecurityBaselineEntity |
| Read Intune Managed Devices | View all Intune managed devices, detected apps, compliance policies, and configurations | Application | IntuneAppInstallStatusEntity , IntuneAppProtectionPolicyEntity , IntuneAutopilotDeviceEntity , IntuneDetectedAppEntity , IntuneDeviceAppEntity , IntuneDeviceComplianceStateEntity , IntuneManagedAppEntity , IntuneManagedDeviceEntity , IntuneTenantEntity |
OneDrive
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all users' full profiles | Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user. | Application | Agent365AgentUserEntity , Deleted User , User , TeamsMemberEntity , TeamsOwnerEntity |
| Read file data | Allows the app to read data in your organization's file. | Application | OneDrive |
| Read items in all site collections | Allows the app to read documents and list items in all site collections without a signed in user. | Application | GroupSiteCollectionEntity , SharePoint Agent , Deleted Site Collection , List/Library , Locked Site Collection , Site Collection , SharePoint Special Group , Site , TeamsSharePointSiteEntity |
OneDrive Permissions
| Permission | Description | Type | Used by |
|---|---|---|---|
| Have full control of all site collections | Allows the app to have full control of all site collections without a signed in user. | Application | File , Folder , File Sharing , SharePoint Group , File Sharing , SpListUserAccessEntity , Redirected Site Collection , File , Folder , SpSiteAdminEntity , SpSiteOwnerEntity , SpSitesUserAccessEntity , SpWebAdminEntity , SpWebOwnerEntity , SpWebUserAccessEntity |
Planner
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all users' tasks and tasklist | Allows the app to read all users' tasks and task lists in your organization, without a signed-in user. | Application | Plan , PlannerPlanMemberEntity , PlannerPlanOwnerEntity |
Power Platform
| Permission | Description | Type | Used by |
|---|---|---|---|
| Access Azure Service Management as you (preview) | Allows the application to access Azure Service Management as you. | Delegated | |
| Access the PowerApps Service API | Accesses all routes in the PowerApps Service API. | Delegated | Connection , Power Apps Custom Connector , Power Platform DLP Connector , Power Platform DLP Policy , Power App (Canvas App) , Environment , Version , Action , Connection , Flow , Environment , Run , Trigger , FlowUserEntity |
Power BI
| Permission | Description | Type | Used by |
|---|---|---|---|
| Access the Power BI content | View all content in tenant | Delegated | Activity Event , App , Artifacts published to Web , Capacity , Dashboard , Dataflow , Dataset , Datamart , Pipeline , Report , Workspace , Unused Artifact |
Security and Compliance
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all published labels and label policies for an organization | Allows an app to read published sensitivity labels and label policy settings for the entire organization or a specific user, without a signed in user. | Application | Sensitivity Label |
Service Health
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read service health | Allows the app to read service health information. | Application |
SharePoint
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read items in all site collections | Allows the app to read documents and list items in all site collections without a signed in user. | Application | GroupSiteCollectionEntity , SharePoint Agent , Deleted Site Collection , List/Library , Locked Site Collection , Site Collection , SharePoint Special Group , Site , TeamsSharePointSiteEntity |
SharePoint Permissions
| Permission | Description | Type | Used by |
|---|---|---|---|
| Have full control of all site collections | Allows the app to have full control of all site collections without a signed in user. | Application | File , Folder , File Sharing , SharePoint Group , File Sharing , SpListUserAccessEntity , Redirected Site Collection , File , Folder , SpSiteAdminEntity , SpSiteOwnerEntity , SpSitesUserAccessEntity , SpWebAdminEntity , SpWebOwnerEntity , SpWebUserAccessEntity |
Teams
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all app catalogs | Allows the app to read the apps in the app catalogs. | Application | App |
| Read all channel messages | Allows the app to read all channel messages in Microsoft Teams, without a signed-in user. | Application | |
| Read all groups | Allows the app to read memberships for all groups without a signed-in user. Also allows the app to read calendar, conversations, files, and other group content for all groups. | Application | Deleted Group , Group , GroupMemberEntity , GroupOwnerEntity , GroupToGroupRelationEntity , Deleted Team , Channel , TeamsChannelMemberEntity , Team , TeamsInstalledAppRelationEntity , TeamsMemberEntity , TeamsOwnerEntity , Tab , VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community |
| Read teams' settings | Read this team's settings, on behalf of the signed-in user. | Application | |
| Read the members of all channels. | Read the members of all channels, without a signed-in user. | Application | Shared Channel External Member , TeamsSharedChannelRelationEntity |
| Read the members of all teams. | Read the members of all teams, without a signed-in user. | Application |
Viva Engage
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all Viva Engage communities | Allows the app to list Viva Engage communities, and to read their properties on behalf of the signed-in user. | Application | VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community |
| Read all groups | Allows the app to read memberships for all groups without a signed-in user. Also allows the app to read calendar, conversations, files, and other group content for all groups. | Application | Deleted Group , Group , GroupMemberEntity , GroupOwnerEntity , GroupToGroupRelationEntity , Deleted Team , Channel , TeamsChannelMemberEntity , Team , TeamsInstalledAppRelationEntity , TeamsMemberEntity , TeamsOwnerEntity , Tab , VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community |
| Read all usage reports | Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Microsoft 365 and Microsoft Entra ID. | Application | Summary of active user (Report) , Trend of daily active user (Report) , Copilot user activity (Report) , User Activity , Usage , User Activity , Device Usage |