Reference

Required Permissions

This article shows the permissions that Rencore Governance Needs.

Rencore Governance needs permissions to your Microsoft 365 tenant in order to operate and collect the data of the services that you would like to govern.

Connect to the tenant

First, you need to connect to your Microsoft 365 tenant to allow Rencore Governance to retrieve the metadata and the current consent status.

You can use any ordinary user account with access to the tenant. No admin permissions are required.

Required permissions

  • User Impersonation (Delegated).

You can learn more about the security of Rencore Governance security overview article.

To get a detailed description of the underlying technical architecture, infrastructure security analysis results from Azure as well as a current application vulnerability assessment report (AVR) generated by a 3rd party (Veracode) please reach out to our sales team.

To allow Rencore Governance to scan your tenant, you need to consent to give it access first.

The app allows you to consent either globally via a single Azure App, or individually by services in order to delegate the consent to various service administrators.

Consent can be given with different accounts than the one used in 1. to connect to the tenant.

  • Global Consent
  • Consent per Service

You can request consent to give Rencore Governance access to your tenant from an admin by clicking the link “Ask Admin for consent”.

This will open your default email client with an email template containing an anonymous consent link

Hi admin,

Could you please approve Rencore Governance to analyze ‘Rencore Governance’ of ‘rencore.com’?

Kindly review the permission requirements and give consent here: https://westeurope.app-qa.rencore.com/consent/72221425083/53abe7d0-215f-4564-bd99-d8c7302ad1a3

Thanks!

When the link is clicked, the admin will be redirected to a consent dialog.

The admin does not gain access to Rencore Governance by giving consent to the service in Microsoft 365.

Consent links will expire after 5 days.

4. Permissions

In order to access the data in your services, several permissions is needed.
You can learn more about Microsoft Graph permissions here.

Rencore Governance uses several apps to allow global or granular permissions.

The permissions are detailed in following article.

Last updated: 2/13/2023