Reference

Microsoft Permissions

The permissions Rencore Governance requests per authenticator, and the inventories that rely on each permission.

Microsoft Agent 365

Permission Description Type Used by
Read Microsoft Intune devices Allows the app to read the properties of devices managed by Microsoft Intune, including the applications detected on them. Application Shadow AI Agent , Shadow AI Detection
Read all Copilot agent and app packages Allows the app to read all agents and apps from the tenant agent registry without a signed-in user. Application Agent Builder Action , CopilotAgentBuilderPackageActionLinkEntity , Agent Builder Capability , CopilotAgentBuilderPackageCapabilityLinkEntity , Agent Builder Element , Agent Builder Agent , Agent Builder Knowledge Source , CopilotAgentBuilderPackageKnowledgeSourceLinkEntity , Agent Action , Agent365AgentPackageActionLinkEntity , Agent Capability , Agent365AgentPackageCapabilityLinkEntity , Agent Element , Agent , Agent Knowledge Source , Agent365AgentPackageKnowledgeSourceLinkEntity
Read all Microsoft Entra agent identities Allows the app to read all Microsoft Entra agent identity objects without a signed-in user. Application Agent Identity
Read all Microsoft Entra agent identity blueprint principals Allows the app to read all Microsoft Entra agent identity blueprint principal objects without a signed-in user. Application Agent Blueprint Principal
Read all Microsoft Entra agent identity blueprints Allows the app to read all Microsoft Entra agent identity blueprint objects without a signed-in user. Application Agent Blueprint , Agent Permission
Read all users' full profiles Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user. Application Agent User , Deleted User , User , TeamsMemberEntity , TeamsOwnerEntity

Auditing

Permission Description Type Used by
Read activity feed Allows to read activity feed. Application
Read all usage reports Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Microsoft 365 and Microsoft Entra ID. Application Summary of active user (Report) , Trend of daily active user (Report) , Copilot user activity (Report) , User Activity , Usage , User Activity , Device Usage
Read audit log Allows to read audit log. Application Risky Entra ID Sign-In , User Registration Credential
Read directory data Allows the app to read data in your organization's directory, such as users, groups and apps, without a signed-in user. Application Registration Certificate , Client secret , Application registration , App Role Assignment , App Role , Deleted App Registration Certificate , Deleted App Client secret , Deleted Application Registration , Deleted Application Verified Publisher , Device , DeviceOwnerEntity , DeviceUserEntity , Directory Role , Domain , Enterprise Registration Certificate , Enterprise App Client secret , Enterprise Application Verified Publisher , Enterprise Application , Enterprise Application OAuth2 Permission Scope , EnterpriseApplicationOwnerEntity , OAuth2 Permission Grant , OAuth2 Permission Scope , Verified Publisher
Read service health Allows the app to read service health information. Application
Read service messages Allows the app to read your tenant's service announcement messages, without a signed-in user. Messages may include information about new or changed features. Application Message Center Message

Entra ID

Permission Description Type Used by
Read directory data Allows the app to read data in your organization's directory, such as users, groups and apps, without a signed-in user. Application Registration Certificate , Client secret , Application registration , App Role Assignment , App Role , Deleted App Registration Certificate , Deleted App Client secret , Deleted Application Registration , Deleted Application Verified Publisher , Device , DeviceOwnerEntity , DeviceUserEntity , Directory Role , Domain , Enterprise Registration Certificate , Enterprise App Client secret , Enterprise Application Verified Publisher , Enterprise Application , Enterprise Application OAuth2 Permission Scope , EnterpriseApplicationOwnerEntity , OAuth2 Permission Grant , OAuth2 Permission Scope , Verified Publisher

Azure

Permission Description Type Used by
Access the Azure API Accesses all routes in the Azure API. Application Advisor Recommendation , Resource Group , AzureResourceGroupOwnerEntity , Subscription , Virtual Machine , Web App , AI Agent , LLM Deployment , Finetune Job , AI Hub , AI Project , AI Service , Daily Costs

Claude

Permission Description Type Used by
Access Claude API View content from workspaces Application Claude File , Claude Model , Claude Skill
Access Claude Admin API View all content in tenant Application Claude API Key , Claude Code Usage , Claude Cost , Claude Invite , Claude Message Usage , ClaudeOrganizationAdminEntity , ClaudeOrganizationBillingUserEntity , ClaudeOrganizationCodeUserEntity , ClaudeOrganizationDeveloperEntity , Claude Organization , ClaudeOrganizationUserEntity , Claude User , Claude Workspace , ClaudeWorkspaceMemberEntity
Modify and view Claude content Read and write all content in Claude Application

Copilot

Permission Description Type Used by
Read all Copilot agent and app packages Allows the app to read all agents and apps from the tenant agent registry without a signed-in user. Application Agent Builder Action , CopilotAgentBuilderPackageActionLinkEntity , Agent Builder Capability , CopilotAgentBuilderPackageCapabilityLinkEntity , Agent Builder Element , Agent Builder Agent , Agent Builder Knowledge Source , CopilotAgentBuilderPackageKnowledgeSourceLinkEntity , Agent Action , Agent365AgentPackageActionLinkEntity , Agent Capability , Agent365AgentPackageCapabilityLinkEntity , Agent Element , Agent , Agent Knowledge Source , Agent365AgentPackageKnowledgeSourceLinkEntity
Read all external connections Allows the app to read all external connections without a signed-in user. Application External Graph Connection
Read all usage reports Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Microsoft 365 and Microsoft Entra ID. Application Summary of active user (Report) , Trend of daily active user (Report) , Copilot user activity (Report) , User Activity , Usage , User Activity , Device Usage
Read audit logs data from all services Allows the app to read and query audit logs from all services. Application
Read user AI enterprise interactions Allows the app to read all AI enterprise interactions. Application M365 Copilot session

Dataverse

Permission Description Type Used by
Access the Dataverse Service API Access Common Data Service as organization users. Application Environment , DataverseEnvironmentEntity
Access the Power Platform admin API Access environment management, tenant settings, and Power Apps management. Application Pay-as-you-go Plan , Tenant Settings
Dataverse Permission prvReadAICopilot Access Common Data Service as organization users. Application Microsoft Copilot
Dataverse Permission prvReadOrganization Access Common Data Service as organization users. Application Power Pages Site , Power Platform Solution
Dataverse Permission prvReadWorkflow Access Common Data Service as organization users. Application Agent Flow
Dataverse Permission prvReadbot Access Common Data Service as organization users. Application Copilot Agent , CustomCopilotMemberEntity
Dataverse Permission prvReadbotcomponent Access Common Data Service as organization users. Application Action , Knowledge , Topic , Trigger
Dataverse Permission prvReadconversationtranscript Access Common Data Service as organization users. Application Agent Conversation

Exchange Admin

Permission Description Type Used by
Manage Exchange As Application Allows the app to call Exchange Online cmdlets via the Admin REST API. Requires an additional Exchange RBAC role assignment in the customer tenant. Application Accepted Domain , Distribution Group , Exchange Organization Configuration , Exchange Role Assignment , Exchange Role Group , ExchangeRoleGroupManagerEntity , ExchangeRoleGroupMemberEntity , Exchange Security Policy , Journal Rule , Mail Contact , Mail Flow Connector , Mail User , Mailbox Audit Bypass , Mailbox Delegate , Mailbox Folder Permission , Mobile Device , Mobile Device Policy , Remote Domain , Resource Mailbox , Transport Rule

Exchange

Permission Description Type Used by
Read all usage reports Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Microsoft 365 and Microsoft Entra ID. Application Summary of active user (Report) , Trend of daily active user (Report) , Copilot user activity (Report) , User Activity , Usage , User Activity , Device Usage
Read calendars in all mailboxes Allows the app to read events of all calendars without a signed-in user. Application Calendar Permission
Read user mailbox settings Allows the app to the read user's mailbox settings. Does not include permission to send mail. Application Redirect Rule , Mailbox

Microsoft 365 All services

Permission Description Type Used by
Read Microsoft Intune devices Allows the app to read the properties of devices managed by Microsoft Intune, including the applications detected on them. Application Shadow AI Agent , Shadow AI Detection
Read activity feed Allows to read activity feed. Application
Read all Copilot agent and app packages Allows the app to read all agents and apps from the tenant agent registry without a signed-in user. Application Agent Builder Action , CopilotAgentBuilderPackageActionLinkEntity , Agent Builder Capability , CopilotAgentBuilderPackageCapabilityLinkEntity , Agent Builder Element , Agent Builder Agent , Agent Builder Knowledge Source , CopilotAgentBuilderPackageKnowledgeSourceLinkEntity , Agent Action , Agent365AgentPackageActionLinkEntity , Agent Capability , Agent365AgentPackageCapabilityLinkEntity , Agent Element , Agent , Agent Knowledge Source , Agent365AgentPackageKnowledgeSourceLinkEntity
Read all Microsoft Entra agent identities Allows the app to read all Microsoft Entra agent identity objects without a signed-in user. Application Agent Identity
Read all Microsoft Entra agent identity blueprint principals Allows the app to read all Microsoft Entra agent identity blueprint principal objects without a signed-in user. Application Agent Blueprint Principal
Read all Microsoft Entra agent identity blueprints Allows the app to read all Microsoft Entra agent identity blueprint objects without a signed-in user. Application Agent Blueprint , Agent Permission
Read all Viva Engage communities Allows the app to list Viva Engage communities, and to read their properties on behalf of the signed-in user. Application VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community
Read all app catalogs Allows the app to read the apps in the app catalogs. Application App
Read all channel messages Allows the app to read all channel messages in Microsoft Teams, without a signed-in user. Application
Read all company places Allows the app to read company places (conference rooms and room lists) for calendar events and other applications. Application Rooms & Equipment
Read all groups Allows the app to read memberships for all groups without a signed-in user. Also allows the app to read calendar, conversations, files, and other group content for all groups. Application Deleted Group , Group , GroupMemberEntity , GroupOwnerEntity , GroupToGroupRelationEntity , Deleted Team , Channel , TeamsChannelMemberEntity , Team , TeamsInstalledAppRelationEntity , TeamsMemberEntity , TeamsOwnerEntity , Tab , VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community
Read all published labels and label policies for an organization Allows an app to read published sensitivity labels and label policy settings for the entire organization or a specific user, without a signed in user. Application Sensitivity Label
Read all usage reports Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Microsoft 365 and Microsoft Entra ID. Application Summary of active user (Report) , Trend of daily active user (Report) , Copilot user activity (Report) , User Activity , Usage , User Activity , Device Usage
Read all users' full profiles Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user. Application Agent User , Deleted User , User , TeamsMemberEntity , TeamsOwnerEntity
Read all users' tasks and tasklist Allows the app to read all users' tasks and task lists in your organization, without a signed-in user. Application Plan , PlannerPlanMemberEntity , PlannerPlanOwnerEntity
Read audit log Allows to read audit log. Application Risky Entra ID Sign-In , User Registration Credential
Read directory data Allows the app to read data in your organization's directory, such as users, groups and apps, without a signed-in user. Application Registration Certificate , Client secret , Application registration , App Role Assignment , App Role , Deleted App Registration Certificate , Deleted App Client secret , Deleted Application Registration , Deleted Application Verified Publisher , Device , DeviceOwnerEntity , DeviceUserEntity , Directory Role , Domain , Enterprise Registration Certificate , Enterprise App Client secret , Enterprise Application Verified Publisher , Enterprise Application , Enterprise Application OAuth2 Permission Scope , EnterpriseApplicationOwnerEntity , OAuth2 Permission Grant , OAuth2 Permission Scope , Verified Publisher
Read file data Allows the app to read data in your organization's file. Application OneDrive
Read items in all site collections Allows the app to read documents and list items in all site collections without a signed in user. Application GroupSiteCollectionEntity , SharePoint Agent , Deleted Site Collection , List/Library , Locked Site Collection , Site Collection , SharePoint Special Group , Site , TeamsSharePointSiteEntity
Read organization information Allows the app to read the organization and related resources, without a signed-in user. Related resources include things like subscribed SKUs and tenant branding information. Application Subscription , Service Assignment , App , UserLicenseEntity , UserServicePlanEntity
Read service health Allows the app to read service health information. Application
Read service messages Allows the app to read your tenant's service announcement messages, without a signed-in user. Messages may include information about new or changed features. Application Message Center Message
Read teams' settings Read this team's settings, on behalf of the signed-in user. Application
Read the members of all channels. Read the members of all channels, without a signed-in user. Application Shared Channel External Member , TeamsSharedChannelRelationEntity
Read the members of all teams. Read the members of all teams, without a signed-in user. Application
Read user mailbox settings Allows the app to the read user's mailbox settings. Does not include permission to send mail. Application Redirect Rule , Mailbox

Microsoft 365

Permission Description Type Used by
Read all company places Allows the app to read company places (conference rooms and room lists) for calendar events and other applications. Application Rooms & Equipment
Read all groups Allows the app to read memberships for all groups without a signed-in user. Also allows the app to read calendar, conversations, files, and other group content for all groups. Application Deleted Group , Group , GroupMemberEntity , GroupOwnerEntity , GroupToGroupRelationEntity , Deleted Team , Channel , TeamsChannelMemberEntity , Team , TeamsInstalledAppRelationEntity , TeamsMemberEntity , TeamsOwnerEntity , Tab , VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community
Read all users' full profiles Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user. Application Agent User , Deleted User , User , TeamsMemberEntity , TeamsOwnerEntity
Read domains Allows the app to read all domain properties without a signed-in user. Application Domain
Read organization information Allows the app to read the organization and related resources, without a signed-in user. Related resources include things like subscribed SKUs and tenant branding information. Application Subscription , Service Assignment , App , UserLicenseEntity , UserServicePlanEntity
Read role management data for Entra ID Allows the app to read the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes reading directory role templates, directory roles and memberships. Application Directory Role

Intune

Permission Description Type Used by
Read Conditional Access Policies View all conditional access policies and device trust configurations Application IntuneConditionalAccessPolicyEntity
Read Intune Audit Events View Intune device management audit events and action history Application IntuneAuditEventEntity
Read Intune Configuration View all Intune device configurations and compliance policies Application IntuneCompliancePolicyEntity , IntuneDeviceCategoryEntity , IntuneDeviceConfigurationEntity , IntuneDeviceConfigurationStateEntity , IntuneDeviceScriptEntity , IntuneSecurityBaselineDeviceStateEntity , IntuneSecurityBaselineEntity
Read Intune Managed Devices View all Intune managed devices, detected apps, compliance policies, and configurations Application IntuneAppInstallStatusEntity , IntuneAppProtectionPolicyEntity , IntuneAutopilotDeviceEntity , IntuneDetectedAppEntity , IntuneDeviceAppEntity , IntuneDeviceComplianceStateEntity , IntuneManagedAppEntity , IntuneManagedDeviceEntity , IntuneTenantEntity

OneDrive

Permission Description Type Used by
Read all users' full profiles Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user. Application Agent User , Deleted User , User , TeamsMemberEntity , TeamsOwnerEntity
Read file data Allows the app to read data in your organization's file. Application OneDrive
Read items in all site collections Allows the app to read documents and list items in all site collections without a signed in user. Application GroupSiteCollectionEntity , SharePoint Agent , Deleted Site Collection , List/Library , Locked Site Collection , Site Collection , SharePoint Special Group , Site , TeamsSharePointSiteEntity

OneDrive Permissions

Permission Description Type Used by
Have full control of all site collections Allows the app to have full control of all site collections without a signed in user. Application File , Folder , File Sharing , SharePoint Group , File Sharing , SpListUserAccessEntity , Redirected Site Collection , File , Folder , SpSiteAdminEntity , SpSiteOwnerEntity , SpSitesUserAccessEntity , SpWebAdminEntity , SpWebOwnerEntity , SpWebUserAccessEntity

OpenAI

Permission Description Type Used by
Access OpenAI API View all content in tenant Application OpenAI File , OpenAI Model
Access OpenAI Admin API View all content in tenant Application OpenAI Admin API Key , OpenAI Assistant , OpenAI Audit Log , OpenAI Chat Completion , OpenAI ChatKit Thread , OpenAI Completion , OpenAI Cost , OpenAI Invite , OpenAI Organization Certificate , OpenAI Organization , OpenAI Project API Key , OpenAI Project Certificate , OpenAI Project , OpenAIProjectMemberEntity , OpenAIProjectOwnerEntity , OpenAI Project Service Account , OpenAI User

Planner

Permission Description Type Used by
Read all users' tasks and tasklist Allows the app to read all users' tasks and task lists in your organization, without a signed-in user. Application Plan , PlannerPlanMemberEntity , PlannerPlanOwnerEntity

Power Platform

Permission Description Type Used by
Access Azure Service Management as you (preview) Allows the application to access Azure Service Management as you. Delegated
Access the PowerApps Service API Accesses all routes in the PowerApps Service API. Delegated Connection , Power Apps Custom Connector , Power Platform DLP Connector , Power Platform DLP Policy , Power App (Canvas App) , Environment , Version , Action , Connection , Flow , Environment , Run , Trigger , FlowUserEntity

Power BI

Permission Description Type Used by
Access the Power BI content View all content in tenant Delegated Activity Event , App , Artifacts published to Web , Capacity , Dashboard , Dataflow , Dataset , Datamart , Pipeline , Report , Workspace , Unused Artifact

Security and Compliance

Permission Description Type Used by
Read all published labels and label policies for an organization Allows an app to read published sensitivity labels and label policy settings for the entire organization or a specific user, without a signed in user. Application Sensitivity Label

Service Health

Permission Description Type Used by
Read service health Allows the app to read service health information. Application

ServiceNow

Permission Description Type Used by
Access ServiceNow API (Read) View all content in ServiceNow instance Application ServiceNow AI Agent , ServiceNowAIAgentToolEntity , ServiceNow AI Execution Plan , ServiceNow AI Execution Task , ServiceNow AI Guardrail , ServiceNow AI Model , ServiceNow AI Skill , ServiceNow AI Team , ServiceNowAITeamMemberEntity , ServiceNow AI Tool , ServiceNow AI Trigger , ServiceNow AI Usage Log , ServiceNow AI Use Case , ServiceNow Instance , ServiceNow User , ServiceNow User Group , ServiceNow User Role
Access ServiceNow API (Read/Write) View and modify all content in ServiceNow instance Application

SharePoint

Permission Description Type Used by
Read items in all site collections Allows the app to read documents and list items in all site collections without a signed in user. Application GroupSiteCollectionEntity , SharePoint Agent , Deleted Site Collection , List/Library , Locked Site Collection , Site Collection , SharePoint Special Group , Site , TeamsSharePointSiteEntity

SharePoint Permissions

Permission Description Type Used by
Have full control of all site collections Allows the app to have full control of all site collections without a signed in user. Application File , Folder , File Sharing , SharePoint Group , File Sharing , SpListUserAccessEntity , Redirected Site Collection , File , Folder , SpSiteAdminEntity , SpSiteOwnerEntity , SpSitesUserAccessEntity , SpWebAdminEntity , SpWebOwnerEntity , SpWebUserAccessEntity

Teams

Permission Description Type Used by
Read all app catalogs Allows the app to read the apps in the app catalogs. Application App
Read all channel messages Allows the app to read all channel messages in Microsoft Teams, without a signed-in user. Application
Read all groups Allows the app to read memberships for all groups without a signed-in user. Also allows the app to read calendar, conversations, files, and other group content for all groups. Application Deleted Group , Group , GroupMemberEntity , GroupOwnerEntity , GroupToGroupRelationEntity , Deleted Team , Channel , TeamsChannelMemberEntity , Team , TeamsInstalledAppRelationEntity , TeamsMemberEntity , TeamsOwnerEntity , Tab , VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community
Read teams' settings Read this team's settings, on behalf of the signed-in user. Application
Read the members of all channels. Read the members of all channels, without a signed-in user. Application Shared Channel External Member , TeamsSharedChannelRelationEntity
Read the members of all teams. Read the members of all teams, without a signed-in user. Application

Viva Engage

Permission Description Type Used by
Read all Viva Engage communities Allows the app to list Viva Engage communities, and to read their properties on behalf of the signed-in user. Application VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community
Read all groups Allows the app to read memberships for all groups without a signed-in user. Also allows the app to read calendar, conversations, files, and other group content for all groups. Application Deleted Group , Group , GroupMemberEntity , GroupOwnerEntity , GroupToGroupRelationEntity , Deleted Team , Channel , TeamsChannelMemberEntity , Team , TeamsInstalledAppRelationEntity , TeamsMemberEntity , TeamsOwnerEntity , Tab , VivaEngageCommunityMemberEntity , VivaEngageCommunityOwnerEntity , Community
Read all usage reports Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Microsoft 365 and Microsoft Entra ID. Application Summary of active user (Report) , Trend of daily active user (Report) , Copilot user activity (Report) , User Activity , Usage , User Activity , Device Usage

Last updated: 7/19/2026