Skip to content

Enterprise Application Permissions

When connecting Kindo to Microsoft services, each integration requires an enterprise application registration in your Azure / Entra ID tenant. The tables below list the exact API permissions each application needs. For which tool uses which permission, see the Microsoft permission reference.

APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Microsoft GrapheDiscovery.Read.AllRead all eDiscovery objects
Microsoft GrapheDiscovery.ReadWrite.AllRead and write all eDiscovery objects
APIPermissionDescription
Microsoft GrapheDiscovery.Read.AllRead all eDiscovery objects
Microsoft GrapheDiscovery.ReadWrite.AllRead and write all eDiscovery objects
APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Microsoft GraphAppRoleAssignment.ReadWrite.AllManage app permission grants and app role assignments
Microsoft GraphAuditLog.Read.AllRead audit log data
Microsoft GraphDirectory.Read.AllRead directory data
Microsoft GraphDirectoryRecommendations.Read.AllRead Azure AD recommendations
Microsoft GraphGroup.Read.AllRead all groups
Microsoft GraphGroupMember.Read.AllRead group memberships
Microsoft GraphPolicy.Read.AllRead your organization’s policies
Microsoft GraphPolicy.Read.AuthenticationMethodRead authentication method policies
Microsoft GraphPolicy.Read.ConditionalAccessRead your organization’s conditional access policies
Microsoft GraphReports.Read.AllRead all usage reports
Microsoft GraphRoleManagement.Read.DirectoryRead directory RBAC settings
Microsoft GraphUser.EnableDisableAccount.AllEnable and disable user accounts
Microsoft GraphUser.Read.AllRead all users’ full profiles
Microsoft GraphUser.ReadBasic.AllRead all users’ basic profiles
APIPermissionDescription
Microsoft GraphAuditLog.Read.AllRead all audit log data
Microsoft GraphDirectory.Read.AllRead directory data
Microsoft GraphDirectoryRecommendations.Read.AllRead all Azure AD recommendations
Microsoft GraphGroup.Read.AllRead all groups
Microsoft GraphGroupMember.Read.AllRead all group memberships
Microsoft GraphPolicy.Read.AllRead your organization’s policies
Microsoft GraphPolicy.Read.AuthenticationMethodRead authentication method policies
Microsoft GraphPolicy.Read.ConditionalAccessRead your organization’s conditional access policies
Microsoft GraphReports.Read.AllRead all usage reports
Microsoft GraphRoleManagement.Read.DirectoryRead all directory RBAC settings
Microsoft GraphUser.EnableDisableAccount.AllEnable and disable user accounts
Microsoft GraphUser.Read.AllRead all users’ full profiles
APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
WindowsDefenderATPAdvancedQuery.ReadRun advanced queries
WindowsDefenderATPAlert.ReadRead alerts
WindowsDefenderATPAlert.ReadWriteRead and write alerts
Microsoft Threat ProtectionIncident.ReadRead incidents
Microsoft Threat ProtectionIncident.ReadWriteRead and write incidents
WindowsDefenderATPMachine.IsolateIsolate machine
WindowsDefenderATPMachine.ReadRead machine information
WindowsDefenderATPMachine.ScanScan machine
WindowsDefenderATPTi.ReadWriteRead and write IOCs
APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Microsoft GraphChannel.ReadBasic.AllRead the names and descriptions of channels
Microsoft GraphChannelMessage.Read.AllRead user channel messages
Microsoft GraphChannelMessage.SendSend channel messages
Microsoft GraphChat.CreateCreate chats
Microsoft GraphChat.ReadRead user chat messages
Microsoft GraphChat.ReadBasicRead names and members of user chat threads
Microsoft GraphChatMessage.SendSend user chat messages
Microsoft GraphFiles.Read.AllRead all files that user can access
Microsoft GraphFiles.ReadWrite.AllHave full access to all files user can access
Microsoft GraphOnlineMeetings.ReadRead user’s online meetings
Microsoft GraphOnlineMeetingTranscript.Read.AllRead all transcripts of online meetings.
Microsoft GraphTeam.ReadBasic.AllRead the names and descriptions of teams
Microsoft GraphUser.ReadBasic.AllRead all users’ basic profiles
APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Microsoft GraphAuditLogsQuery.Read.AllRead audit logs data from all services
Microsoft GraphContent.Process.UserProcess content for data security, governance and compliance
Microsoft GraphFiles.ReadWrite.AllHave full access to all files user can access
Microsoft GraphInformationProtectionPolicy.ReadRead user sensitivity labels and label policies.
Microsoft GraphProtectionScopes.Compute.UserCompute Purview policies for an individual user
Microsoft GraphSecurityAlert.Read.AllRead all security alerts
Microsoft GraphSecurityAlert.ReadWrite.AllRead and write to all security alerts
Microsoft GraphSecurityIncident.Read.AllRead incidents
Microsoft GraphSecurityIncident.ReadWrite.AllRead and write to incidents
Microsoft GraphThreatHunting.Read.AllRun hunting queries
APIPermissionDescription
Microsoft GraphAuditLogsQuery.Read.AllRead audit logs data from all services
Microsoft GraphContent.Process.UserProcess content for data security, governance and compliance
Microsoft GraphFiles.ReadWrite.AllRead and write files in all site collections
Microsoft GraphInformationProtectionPolicy.Read.AllRead all published labels and label policies for an organization.
Microsoft GraphProtectionScopes.Compute.AllCompute Purview policies at tenant scope
Microsoft GraphSecurityAlert.Read.AllRead all security alerts
Microsoft GraphSecurityAlert.ReadWrite.AllRead and write to all security alerts
Microsoft GraphSecurityIncident.Read.AllRead all security incidents
Microsoft GraphSecurityIncident.ReadWrite.AllRead and write to all security incidents
Microsoft GraphThreatHunting.Read.AllRun hunting queries
APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Microsoft PurviewPurview.DelegatedAccessPurview Delegated API Access

The signed-in user also needs a Purview collection role (Data Reader, Data Curator, Data Source Administrator, or Collection Admin depending on the tools used).

APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Microsoft GraphDeviceManagementApps.Read.AllRead Microsoft Intune apps
Microsoft GraphDeviceManagementConfiguration.Read.AllRead Microsoft Intune Device Configuration and Policies
Microsoft GraphDeviceManagementManagedDevices.PrivilegedOperations.AllPerform user-impacting remote actions on Microsoft Intune devices
Microsoft GraphDeviceManagementManagedDevices.Read.AllRead Microsoft Intune devices
APIPermissionDescription
Microsoft GraphDeviceManagementApps.Read.AllRead Microsoft Intune apps
Microsoft GraphDeviceManagementConfiguration.Read.AllRead Microsoft Intune device configuration and policies
Microsoft GraphDeviceManagementManagedDevices.PrivilegedOperations.AllPerform user-impacting remote actions on Microsoft Intune devices
Microsoft GraphDeviceManagementManagedDevices.Read.AllRead Microsoft Intune devices
APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Microsoft GraphCalendars.ReadRead user calendars
Microsoft GraphCalendars.Read.SharedRead user and shared calendars
Microsoft GraphCalendars.ReadBasicRead basic details of user calendars
Microsoft GraphCalendars.ReadWriteHave full access to user calendars
APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Microsoft GraphCalendars.ReadRead user calendars
Microsoft GraphCalendars.Read.SharedRead user and shared calendars
Microsoft GraphCalendars.ReadBasicRead basic details of user calendars
Microsoft GraphCalendars.ReadWriteHave full access to user calendars
Microsoft GraphContacts.ReadRead user contacts
Microsoft GraphMail.ReadRead user mail
Microsoft GraphMail.ReadBasicRead user basic mail
Microsoft GraphMail.SendSend mail as a user
Microsoft GraphPeople.ReadRead users’ relevant people lists
APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Microsoft GraphAccessReview.Read.AllRead all access reviews that user can access
Microsoft GraphAccessReview.ReadWrite.AllManage all access reviews that user can access
Microsoft GraphEntitlementManagement.Read.AllRead all entitlement management resources
Microsoft GraphEntitlementManagement.ReadWrite.AllRead and write entitlement management resources
Microsoft GraphLifecycleWorkflows-Reports.Read.AllRead all Lifecycle workflows reports
Microsoft GraphLifecycleWorkflows-Workflow.ActivateRun workflows on-demand in Lifecycle workflows
Microsoft GraphLifecycleWorkflows-Workflow.ReadBasic.AllList all workflows in Lifecycle workflows
Microsoft GraphPrivilegedAssignmentSchedule.Read.AzureADGroupRead assignment schedules for access to Azure AD groups
Microsoft GraphPrivilegedAssignmentSchedule.ReadWrite.AzureADGroupRead, create, and delete assignment schedules for access to Azure AD groups
Microsoft GraphPrivilegedEligibilitySchedule.Read.AzureADGroupRead eligibility schedules for access to Azure AD groups
Microsoft GraphPrivilegedEligibilitySchedule.ReadWrite.AzureADGroupRead, create, and delete eligibility schedules for access to Azure AD groups
Microsoft GraphRoleAssignmentSchedule.Read.DirectoryRead all active role assignments for your company’s directory
Microsoft GraphRoleAssignmentSchedule.ReadWrite.DirectoryRead, update, and delete all active role assignments for your company’s directory
Microsoft GraphRoleEligibilitySchedule.Read.DirectoryRead all eligible role assignments for your company’s directory
Microsoft GraphRoleEligibilitySchedule.ReadWrite.DirectoryRead, update, and delete all eligible role assignments for your company’s directory
Microsoft GraphRoleManagement.Read.DirectoryRead directory RBAC settings
APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Microsoft GraphFiles.ReadRead user files
Microsoft GraphFiles.ReadWriteHave full access to user files
APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Microsoft GraphIdentityRiskyUser.Read.AllRead identity risky user information
Microsoft GraphIdentityRiskyUser.ReadWrite.AllRead and write risky user information
Microsoft GraphSecurityAlert.Read.AllRead all security alerts
Microsoft GraphSecurityAlert.ReadWrite.AllRead and write to all security alerts
Microsoft GraphSecurityEvents.Read.AllRead your organization’s security events
Microsoft GraphSecurityIncident.Read.AllRead incidents
Microsoft GraphSecurityIncident.ReadWrite.AllRead and write to incidents
Microsoft GraphThreatHunting.Read.AllRun hunting queries
APIPermissionDescription
Microsoft GraphIdentityRiskyUser.Read.AllRead all identity risky user information
Microsoft GraphIdentityRiskyUser.ReadWrite.AllRead and write all risky user information
Microsoft GraphSecurityAlert.Read.AllRead all security alerts
Microsoft GraphSecurityAlert.ReadWrite.AllRead and write to all security alerts
Microsoft GraphSecurityEvents.Read.AllRead your organization’s security events
Microsoft GraphSecurityIncident.Read.AllRead all security incidents
Microsoft GraphSecurityIncident.ReadWrite.AllRead and write to all security incidents
Microsoft GraphThreatHunting.Read.AllRun hunting queries
APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Microsoft GraphFiles.ReadRead user files
Microsoft GraphFiles.Read.AllRead all files that user can access
Microsoft GraphFiles.ReadWrite.AllHave full access to all files user can access
APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Microsoft GraphFiles.ReadRead user files
Microsoft GraphFiles.ReadWriteHave full access to user files
Microsoft GraphSites.Read.AllRead items in all site collections
Microsoft GraphSites.ReadWrite.AllEdit or delete items in all site collections
APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Azure Service Managementuser_impersonationAccess Azure Service Management as organization users (preview)

None. Azure Resource Manager has no application permissions; access comes from the Azure RBAC role below.

The signed-in user (or, in application mode, the app itself) also needs the Reader Azure RBAC role on the subscription or management group. Application mode needs no API permissions.

APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Azure Service Managementuser_impersonationAccess Azure Service Management as organization users (preview)

The signed-in user also needs the Security Reader Azure RBAC role, or Security Admin to update alerts.

APIPermissionDescription
Microsoft GraphUser.ReadSign in and read user profile
Microsoft Graphoffline_accessMaintain access to data you have given it access to
Azure Service Managementuser_impersonationAccess Azure Service Management as organization users (preview)

The signed-in user also needs the Microsoft Sentinel Reader Azure RBAC role, or Microsoft Sentinel Responder to update incidents and create bookmarks.