Reference
Microsoft Permissions
The permissions Rencore Governance requests per authenticator, and the inventories that rely on each permission.
Microsoft Agent 365
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read Microsoft Intune devices | Allows the app to read the properties of devices managed by Microsoft Intune, including the applications detected on them. | Application | Shadow AI Agent , Shadow AI Detection |
| Read all Copilot agent and app packages | Allows the app to read all agents and apps from the tenant agent registry without a signed-in user. | Application | Agent Builder Action , CopilotAgentBuilderPackageActionLinkEntity , Agent Builder Capability , CopilotAgentBuilderPackageCapabilityLinkEntity , Agent Builder Element , Agent Builder Agent , Agent Builder Knowledge Source , CopilotAgentBuilderPackageKnowledgeSourceLinkEntity , Agent Action , Agent365AgentPackageActionLinkEntity , Agent Capability , Agent365AgentPackageCapabilityLinkEntity , Agent Element , Agent , Agent Knowledge Source , Agent365AgentPackageKnowledgeSourceLinkEntity |
| Read all Microsoft Entra agent identities | Allows the app to read all Microsoft Entra agent identity objects without a signed-in user. | Application | Agent Identity |
| Read all Microsoft Entra agent identity blueprint principals | Allows the app to read all Microsoft Entra agent identity blueprint principal objects without a signed-in user. | Application | Agent Blueprint Principal |
| Read all Microsoft Entra agent identity blueprints | Allows the app to read all Microsoft Entra agent identity blueprint objects without a signed-in user. | Application | Agent Blueprint , Agent Permission |
| Read all users' full profiles | Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user. | Application | Agent User , Deleted User , User , TeamsMemberEntity , TeamsOwnerEntity |
Auditing
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read activity feed | Allows to read activity feed. | Application | |
| Read all usage reports | Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Microsoft 365 and Microsoft Entra ID. | Application | Summary of active user (Report) , Trend of daily active user (Report) , Copilot user activity (Report) , User Activity , Usage , User Activity , Device Usage |
| Read audit log | Allows to read audit log. | Application | Risky Entra ID Sign-In , User Registration Credential |
| Read directory data | Allows the app to read data in your organization's directory, such as users, groups and apps, without a signed-in user. | Application | Registration Certificate , Client secret , Application registration , App Role Assignment , App Role , Deleted App Registration Certificate , Deleted App Client secret , Deleted Application Registration , Deleted Application Verified Publisher , Device , DeviceOwnerEntity , DeviceUserEntity , Directory Role , Domain , Enterprise Registration Certificate , Enterprise App Client secret , Enterprise Application Verified Publisher , Enterprise Application , Enterprise Application OAuth2 Permission Scope , EnterpriseApplicationOwnerEntity , OAuth2 Permission Grant , OAuth2 Permission Scope , Verified Publisher |
| Read service health | Allows the app to read service health information. | Application | |
| Read service messages | Allows the app to read your tenant's service announcement messages, without a signed-in user. Messages may include information about new or changed features. | Application | Message Center Message |
Entra ID
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read directory data | Allows the app to read data in your organization's directory, such as users, groups and apps, without a signed-in user. | Application | Registration Certificate , Client secret , Application registration , App Role Assignment , App Role , Deleted App Registration Certificate , Deleted App Client secret , Deleted Application Registration , Deleted Application Verified Publisher , Device , DeviceOwnerEntity , DeviceUserEntity , Directory Role , Domain , Enterprise Registration Certificate , Enterprise App Client secret , Enterprise Application Verified Publisher , Enterprise Application , Enterprise Application OAuth2 Permission Scope , EnterpriseApplicationOwnerEntity , OAuth2 Permission Grant , OAuth2 Permission Scope , Verified Publisher |
Azure
| Permission | Description | Type | Used by |
|---|---|---|---|
| Access the Azure API | Accesses all routes in the Azure API. | Application | Advisor Recommendation , Resource Group , AzureResourceGroupOwnerEntity , Subscription , Virtual Machine , Web App , AI Agent , LLM Deployment , Finetune Job , AI Hub , AI Project , AI Service , Daily Costs |
Claude
| Permission | Description | Type | Used by |
|---|---|---|---|
| Access Claude API | View content from workspaces | Application | Claude File , Claude Model , Claude Skill |
| Access Claude Admin API | View all content in tenant | Application | Claude API Key , Claude Code Usage , Claude Cost , Claude Invite , Claude Message Usage , ClaudeOrganizationAdminEntity , ClaudeOrganizationBillingUserEntity , ClaudeOrganizationCodeUserEntity , ClaudeOrganizationDeveloperEntity , Claude Organization , ClaudeOrganizationUserEntity , Claude User , Claude Workspace , ClaudeWorkspaceMemberEntity |
| Modify and view Claude content | Read and write all content in Claude | Application |
Copilot
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all Copilot agent and app packages | Allows the app to read all agents and apps from the tenant agent registry without a signed-in user. | Application | Agent Builder Action , CopilotAgentBuilderPackageActionLinkEntity , Agent Builder Capability , CopilotAgentBuilderPackageCapabilityLinkEntity , Agent Builder Element , Agent Builder Agent , Agent Builder Knowledge Source , CopilotAgentBuilderPackageKnowledgeSourceLinkEntity , Agent Action , Agent365AgentPackageActionLinkEntity , Agent Capability , Agent365AgentPackageCapabilityLinkEntity , Agent Element , Agent , Agent Knowledge Source , Agent365AgentPackageKnowledgeSourceLinkEntity |
| Read all external connections | Allows the app to read all external connections without a signed-in user. | Application | External Graph Connection |
| Read all usage reports | Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Microsoft 365 and Microsoft Entra ID. | Application | Summary of active user (Report) , Trend of daily active user (Report) , Copilot user activity (Report) , User Activity , Usage , User Activity , Device Usage |
| Read audit logs data from all services | Allows the app to read and query audit logs from all services. | Application | |
| Read user AI enterprise interactions | Allows the app to read all AI enterprise interactions. | Application | M365 Copilot session |
Dataverse
| Permission | Description | Type | Used by |
|---|---|---|---|
| Access the Dataverse Service API | Access Common Data Service as organization users. | Application | Environment , DataverseEnvironmentEntity |
| Access the Power Platform admin API | Access environment management, tenant settings, and Power Apps management. | Application | Pay-as-you-go Plan , Tenant Settings |
| Dataverse Permission prvReadAICopilot | Access Common Data Service as organization users. | Application | Microsoft Copilot |
| Dataverse Permission prvReadOrganization | Access Common Data Service as organization users. | Application | Power Pages Site , Power Platform Solution |
| Dataverse Permission prvReadWorkflow | Access Common Data Service as organization users. | Application | Agent Flow |
| Dataverse Permission prvReadbot | Access Common Data Service as organization users. | Application | Copilot Agent , CustomCopilotMemberEntity |
| Dataverse Permission prvReadbotcomponent | Access Common Data Service as organization users. | Application | Action , Knowledge , Topic , Trigger |
| Dataverse Permission prvReadconversationtranscript | Access Common Data Service as organization users. | Application | Agent Conversation |
Exchange Admin
| Permission | Description | Type | Used by |
|---|---|---|---|
| Manage Exchange As Application | Allows the app to call Exchange Online cmdlets via the Admin REST API. Requires an additional Exchange RBAC role assignment in the customer tenant. | Application | Accepted Domain , Distribution Group , Exchange Organization Configuration , Exchange Role Assignment , Exchange Role Group , ExchangeRoleGroupManagerEntity , ExchangeRoleGroupMemberEntity , Exchange Security Policy , Journal Rule , Mail Contact , Mail Flow Connector , Mail User , Mailbox Audit Bypass , Mailbox Delegate , Mailbox Folder Permission , Mobile Device , Mobile Device Policy , Remote Domain , Resource Mailbox , Transport Rule |
Exchange
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all usage reports | Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Microsoft 365 and Microsoft Entra ID. | Application | Summary of active user (Report) , Trend of daily active user (Report) , Copilot user activity (Report) , User Activity , Usage , User Activity , Device Usage |
| Read calendars in all mailboxes | Allows the app to read events of all calendars without a signed-in user. | Application | Calendar Permission |
| Read user mailbox settings | Allows the app to the read user's mailbox settings. Does not include permission to send mail. | Application | Redirect Rule , Mailbox |
Microsoft 365 All services
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read Microsoft Intune devices | Allows the app to read the properties of devices managed by Microsoft Intune, including the applications detected on them. | Application | Shadow AI Agent , Shadow AI Detection |
| Read activity feed | Allows to read activity feed. | Application | |
| Read all Copilot agent and app packages | Allows the app to read all agents and apps from the tenant agent registry without a signed-in user. | Application | Agent Builder Action , CopilotAgentBuilderPackageActionLinkEntity , Agent Builder Capability , CopilotAgentBuilderPackageCapabilityLinkEntity , Agent Builder Element , Agent Builder Agent , Agent Builder Knowledge Source , CopilotAgentBuilderPackageKnowledgeSourceLinkEntity , Agent Action , Agent365AgentPackageActionLinkEntity , Agent Capability , Agent365AgentPackageCapabilityLinkEntity , Agent Element , Agent , Agent Knowledge Source , Agent365AgentPackageKnowledgeSourceLinkEntity |
| Read all Microsoft Entra agent identities | Allows the app to read all Microsoft Entra agent identity objects without a signed-in user. | Application | Agent Identity |
| Read all Microsoft Entra agent identity blueprint principals | Allows the app to read all Microsoft Entra agent identity blueprint principal objects without a signed-in user. | Application | Agent Blueprint Principal |
| Read all Microsoft Entra agent identity blueprints | Allows the app to read all Microsoft Entra agent identity blueprint objects without a signed-in user. | Application | Agent Blueprint , Agent Permission |
| Read all Viva Engage communities | Allows the app to list Viva Engage communities, and to read their properties on behalf of the signed-in user. | Application | VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community |
| Read all app catalogs | Allows the app to read the apps in the app catalogs. | Application | App |
| Read all channel messages | Allows the app to read all channel messages in Microsoft Teams, without a signed-in user. | Application | |
| Read all company places | Allows the app to read company places (conference rooms and room lists) for calendar events and other applications. | Application | Rooms & Equipment |
| Read all groups | Allows the app to read memberships for all groups without a signed-in user. Also allows the app to read calendar, conversations, files, and other group content for all groups. | Application | Deleted Group , Group , GroupMemberEntity , GroupOwnerEntity , GroupToGroupRelationEntity , Deleted Team , Channel , TeamsChannelMemberEntity , Team , TeamsInstalledAppRelationEntity , TeamsMemberEntity , TeamsOwnerEntity , Tab , VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community |
| Read all published labels and label policies for an organization | Allows an app to read published sensitivity labels and label policy settings for the entire organization or a specific user, without a signed in user. | Application | Sensitivity Label |
| Read all usage reports | Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Microsoft 365 and Microsoft Entra ID. | Application | Summary of active user (Report) , Trend of daily active user (Report) , Copilot user activity (Report) , User Activity , Usage , User Activity , Device Usage |
| Read all users' full profiles | Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user. | Application | Agent User , Deleted User , User , TeamsMemberEntity , TeamsOwnerEntity |
| Read all users' tasks and tasklist | Allows the app to read all users' tasks and task lists in your organization, without a signed-in user. | Application | Plan , PlannerPlanMemberEntity , PlannerPlanOwnerEntity |
| Read audit log | Allows to read audit log. | Application | Risky Entra ID Sign-In , User Registration Credential |
| Read directory data | Allows the app to read data in your organization's directory, such as users, groups and apps, without a signed-in user. | Application | Registration Certificate , Client secret , Application registration , App Role Assignment , App Role , Deleted App Registration Certificate , Deleted App Client secret , Deleted Application Registration , Deleted Application Verified Publisher , Device , DeviceOwnerEntity , DeviceUserEntity , Directory Role , Domain , Enterprise Registration Certificate , Enterprise App Client secret , Enterprise Application Verified Publisher , Enterprise Application , Enterprise Application OAuth2 Permission Scope , EnterpriseApplicationOwnerEntity , OAuth2 Permission Grant , OAuth2 Permission Scope , Verified Publisher |
| Read file data | Allows the app to read data in your organization's file. | Application | OneDrive |
| Read items in all site collections | Allows the app to read documents and list items in all site collections without a signed in user. | Application | GroupSiteCollectionEntity , SharePoint Agent , Deleted Site Collection , List/Library , Locked Site Collection , Site Collection , SharePoint Special Group , Site , TeamsSharePointSiteEntity |
| Read organization information | Allows the app to read the organization and related resources, without a signed-in user. Related resources include things like subscribed SKUs and tenant branding information. | Application | Subscription , Service Assignment , App , UserLicenseEntity , UserServicePlanEntity |
| Read service health | Allows the app to read service health information. | Application | |
| Read service messages | Allows the app to read your tenant's service announcement messages, without a signed-in user. Messages may include information about new or changed features. | Application | Message Center Message |
| Read teams' settings | Read this team's settings, on behalf of the signed-in user. | Application | |
| Read the members of all channels. | Read the members of all channels, without a signed-in user. | Application | Shared Channel External Member , TeamsSharedChannelRelationEntity |
| Read the members of all teams. | Read the members of all teams, without a signed-in user. | Application | |
| Read user mailbox settings | Allows the app to the read user's mailbox settings. Does not include permission to send mail. | Application | Redirect Rule , Mailbox |
Microsoft 365
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all company places | Allows the app to read company places (conference rooms and room lists) for calendar events and other applications. | Application | Rooms & Equipment |
| Read all groups | Allows the app to read memberships for all groups without a signed-in user. Also allows the app to read calendar, conversations, files, and other group content for all groups. | Application | Deleted Group , Group , GroupMemberEntity , GroupOwnerEntity , GroupToGroupRelationEntity , Deleted Team , Channel , TeamsChannelMemberEntity , Team , TeamsInstalledAppRelationEntity , TeamsMemberEntity , TeamsOwnerEntity , Tab , VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community |
| Read all users' full profiles | Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user. | Application | Agent User , Deleted User , User , TeamsMemberEntity , TeamsOwnerEntity |
| Read domains | Allows the app to read all domain properties without a signed-in user. | Application | Domain |
| Read organization information | Allows the app to read the organization and related resources, without a signed-in user. Related resources include things like subscribed SKUs and tenant branding information. | Application | Subscription , Service Assignment , App , UserLicenseEntity , UserServicePlanEntity |
| Read role management data for Entra ID | Allows the app to read the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes reading directory role templates, directory roles and memberships. | Application | Directory Role |
Intune
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read Conditional Access Policies | View all conditional access policies and device trust configurations | Application | IntuneConditionalAccessPolicyEntity |
| Read Intune Audit Events | View Intune device management audit events and action history | Application | IntuneAuditEventEntity |
| Read Intune Configuration | View all Intune device configurations and compliance policies | Application | IntuneCompliancePolicyEntity , IntuneDeviceCategoryEntity , IntuneDeviceConfigurationEntity , IntuneDeviceConfigurationStateEntity , IntuneDeviceScriptEntity , IntuneSecurityBaselineDeviceStateEntity , IntuneSecurityBaselineEntity |
| Read Intune Managed Devices | View all Intune managed devices, detected apps, compliance policies, and configurations | Application | IntuneAppInstallStatusEntity , IntuneAppProtectionPolicyEntity , IntuneAutopilotDeviceEntity , IntuneDetectedAppEntity , IntuneDeviceAppEntity , IntuneDeviceComplianceStateEntity , IntuneManagedAppEntity , IntuneManagedDeviceEntity , IntuneTenantEntity |
OneDrive
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all users' full profiles | Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user. | Application | Agent User , Deleted User , User , TeamsMemberEntity , TeamsOwnerEntity |
| Read file data | Allows the app to read data in your organization's file. | Application | OneDrive |
| Read items in all site collections | Allows the app to read documents and list items in all site collections without a signed in user. | Application | GroupSiteCollectionEntity , SharePoint Agent , Deleted Site Collection , List/Library , Locked Site Collection , Site Collection , SharePoint Special Group , Site , TeamsSharePointSiteEntity |
OneDrive Permissions
| Permission | Description | Type | Used by |
|---|---|---|---|
| Have full control of all site collections | Allows the app to have full control of all site collections without a signed in user. | Application | File , Folder , File Sharing , SharePoint Group , File Sharing , SpListUserAccessEntity , Redirected Site Collection , File , Folder , SpSiteAdminEntity , SpSiteOwnerEntity , SpSitesUserAccessEntity , SpWebAdminEntity , SpWebOwnerEntity , SpWebUserAccessEntity |
OpenAI
| Permission | Description | Type | Used by |
|---|---|---|---|
| Access OpenAI API | View all content in tenant | Application | OpenAI File , OpenAI Model |
| Access OpenAI Admin API | View all content in tenant | Application | OpenAI Admin API Key , OpenAI Assistant , OpenAI Audit Log , OpenAI Chat Completion , OpenAI ChatKit Thread , OpenAI Completion , OpenAI Cost , OpenAI Invite , OpenAI Organization Certificate , OpenAI Organization , OpenAI Project API Key , OpenAI Project Certificate , OpenAI Project , OpenAIProjectMemberEntity , OpenAIProjectOwnerEntity , OpenAI Project Service Account , OpenAI User |
Planner
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all users' tasks and tasklist | Allows the app to read all users' tasks and task lists in your organization, without a signed-in user. | Application | Plan , PlannerPlanMemberEntity , PlannerPlanOwnerEntity |
Power Platform
| Permission | Description | Type | Used by |
|---|---|---|---|
| Access Azure Service Management as you (preview) | Allows the application to access Azure Service Management as you. | Delegated | |
| Access the PowerApps Service API | Accesses all routes in the PowerApps Service API. | Delegated | Connection , Power Apps Custom Connector , Power Platform DLP Connector , Power Platform DLP Policy , Power App (Canvas App) , Environment , Version , Action , Connection , Flow , Environment , Run , Trigger , FlowUserEntity |
Power BI
| Permission | Description | Type | Used by |
|---|---|---|---|
| Access the Power BI content | View all content in tenant | Delegated | Activity Event , App , Artifacts published to Web , Capacity , Dashboard , Dataflow , Dataset , Datamart , Pipeline , Report , Workspace , Unused Artifact |
Security and Compliance
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all published labels and label policies for an organization | Allows an app to read published sensitivity labels and label policy settings for the entire organization or a specific user, without a signed in user. | Application | Sensitivity Label |
Service Health
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read service health | Allows the app to read service health information. | Application |
ServiceNow
| Permission | Description | Type | Used by |
|---|---|---|---|
| Access ServiceNow API (Read) | View all content in ServiceNow instance | Application | ServiceNow AI Agent , ServiceNowAIAgentToolEntity , ServiceNow AI Execution Plan , ServiceNow AI Execution Task , ServiceNow AI Guardrail , ServiceNow AI Model , ServiceNow AI Skill , ServiceNow AI Team , ServiceNowAITeamMemberEntity , ServiceNow AI Tool , ServiceNow AI Trigger , ServiceNow AI Usage Log , ServiceNow AI Use Case , ServiceNow Instance , ServiceNow User , ServiceNow User Group , ServiceNow User Role |
| Access ServiceNow API (Read/Write) | View and modify all content in ServiceNow instance | Application |
SharePoint
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read items in all site collections | Allows the app to read documents and list items in all site collections without a signed in user. | Application | GroupSiteCollectionEntity , SharePoint Agent , Deleted Site Collection , List/Library , Locked Site Collection , Site Collection , SharePoint Special Group , Site , TeamsSharePointSiteEntity |
SharePoint Permissions
| Permission | Description | Type | Used by |
|---|---|---|---|
| Have full control of all site collections | Allows the app to have full control of all site collections without a signed in user. | Application | File , Folder , File Sharing , SharePoint Group , File Sharing , SpListUserAccessEntity , Redirected Site Collection , File , Folder , SpSiteAdminEntity , SpSiteOwnerEntity , SpSitesUserAccessEntity , SpWebAdminEntity , SpWebOwnerEntity , SpWebUserAccessEntity |
Teams
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all app catalogs | Allows the app to read the apps in the app catalogs. | Application | App |
| Read all channel messages | Allows the app to read all channel messages in Microsoft Teams, without a signed-in user. | Application | |
| Read all groups | Allows the app to read memberships for all groups without a signed-in user. Also allows the app to read calendar, conversations, files, and other group content for all groups. | Application | Deleted Group , Group , GroupMemberEntity , GroupOwnerEntity , GroupToGroupRelationEntity , Deleted Team , Channel , TeamsChannelMemberEntity , Team , TeamsInstalledAppRelationEntity , TeamsMemberEntity , TeamsOwnerEntity , Tab , VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community |
| Read teams' settings | Read this team's settings, on behalf of the signed-in user. | Application | |
| Read the members of all channels. | Read the members of all channels, without a signed-in user. | Application | Shared Channel External Member , TeamsSharedChannelRelationEntity |
| Read the members of all teams. | Read the members of all teams, without a signed-in user. | Application |
Viva Engage
| Permission | Description | Type | Used by |
|---|---|---|---|
| Read all Viva Engage communities | Allows the app to list Viva Engage communities, and to read their properties on behalf of the signed-in user. | Application | VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community |
| Read all groups | Allows the app to read memberships for all groups without a signed-in user. Also allows the app to read calendar, conversations, files, and other group content for all groups. | Application | Deleted Group , Group , GroupMemberEntity , GroupOwnerEntity , GroupToGroupRelationEntity , Deleted Team , Channel , TeamsChannelMemberEntity , Team , TeamsInstalledAppRelationEntity , TeamsMemberEntity , TeamsOwnerEntity , Tab , VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community |
| Read all usage reports | Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Microsoft 365 and Microsoft Entra ID. | Application | Summary of active user (Report) , Trend of daily active user (Report) , Copilot user activity (Report) , User Activity , Usage , User Activity , Device Usage |