When connecting Kindo to Microsoft services, each integration requires an enterprise application registration in your Azure / Entra ID tenant. The tables below list the exact API permissions each application needs. For which tool uses which permission, see the Microsoft permission reference .
Note
Your tenant administrator must grant these permissions before users can authenticate. Depending on the integration, permissions may be delegated (act on behalf of a signed-in user) or application (act as the service itself). Where an integration supports both, they are called out separately. Application permissions always require admin consent.
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Microsoft Graph eDiscovery.Read.All Read all eDiscovery objects Microsoft Graph eDiscovery.ReadWrite.All Read and write all eDiscovery objects
API Permission Description Microsoft Graph eDiscovery.Read.All Read all eDiscovery objects Microsoft Graph eDiscovery.ReadWrite.All Read and write all eDiscovery objects
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Microsoft Graph AppRoleAssignment.ReadWrite.All Manage app permission grants and app role assignments Microsoft Graph AuditLog.Read.All Read audit log data Microsoft Graph Directory.Read.All Read directory data Microsoft Graph DirectoryRecommendations.Read.All Read Azure AD recommendations Microsoft Graph Group.Read.All Read all groups Microsoft Graph GroupMember.Read.All Read group memberships Microsoft Graph Policy.Read.All Read your organization’s policies Microsoft Graph Policy.Read.AuthenticationMethod Read authentication method policies Microsoft Graph Policy.Read.ConditionalAccess Read your organization’s conditional access policies Microsoft Graph Reports.Read.All Read all usage reports Microsoft Graph RoleManagement.Read.Directory Read directory RBAC settings Microsoft Graph User.EnableDisableAccount.All Enable and disable user accounts Microsoft Graph User.Read.All Read all users’ full profiles Microsoft Graph User.ReadBasic.All Read all users’ basic profiles
API Permission Description Microsoft Graph AuditLog.Read.All Read all audit log data Microsoft Graph Directory.Read.All Read directory data Microsoft Graph DirectoryRecommendations.Read.All Read all Azure AD recommendations Microsoft Graph Group.Read.All Read all groups Microsoft Graph GroupMember.Read.All Read all group memberships Microsoft Graph Policy.Read.All Read your organization’s policies Microsoft Graph Policy.Read.AuthenticationMethod Read authentication method policies Microsoft Graph Policy.Read.ConditionalAccess Read your organization’s conditional access policies Microsoft Graph Reports.Read.All Read all usage reports Microsoft Graph RoleManagement.Read.Directory Read all directory RBAC settings Microsoft Graph User.EnableDisableAccount.All Enable and disable user accounts Microsoft Graph User.Read.All Read all users’ full profiles
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to WindowsDefenderATP AdvancedQuery.Read Run advanced queries WindowsDefenderATP Alert.Read Read alerts WindowsDefenderATP Alert.ReadWrite Read and write alerts Microsoft Threat Protection Incident.Read Read incidents Microsoft Threat Protection Incident.ReadWrite Read and write incidents WindowsDefenderATP Machine.Isolate Isolate machine WindowsDefenderATP Machine.Read Read machine information WindowsDefenderATP Machine.Scan Scan machine WindowsDefenderATP Ti.ReadWrite Read and write IOCs
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Microsoft Graph Channel.ReadBasic.All Read the names and descriptions of channels Microsoft Graph ChannelMessage.Read.All Read user channel messages Microsoft Graph ChannelMessage.Send Send channel messages Microsoft Graph Chat.Create Create chats Microsoft Graph Chat.Read Read user chat messages Microsoft Graph Chat.ReadBasic Read names and members of user chat threads Microsoft Graph ChatMessage.Send Send user chat messages Microsoft Graph Files.Read.All Read all files that user can access Microsoft Graph Files.ReadWrite.All Have full access to all files user can access Microsoft Graph OnlineMeetings.Read Read user’s online meetings Microsoft Graph OnlineMeetingTranscript.Read.All Read all transcripts of online meetings. Microsoft Graph Team.ReadBasic.All Read the names and descriptions of teams Microsoft Graph User.ReadBasic.All Read all users’ basic profiles
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Microsoft Graph AuditLogsQuery.Read.All Read audit logs data from all services Microsoft Graph Content.Process.User Process content for data security, governance and compliance Microsoft Graph Files.ReadWrite.All Have full access to all files user can access Microsoft Graph InformationProtectionPolicy.Read Read user sensitivity labels and label policies. Microsoft Graph ProtectionScopes.Compute.User Compute Purview policies for an individual user Microsoft Graph SecurityAlert.Read.All Read all security alerts Microsoft Graph SecurityAlert.ReadWrite.All Read and write to all security alerts Microsoft Graph SecurityIncident.Read.All Read incidents Microsoft Graph SecurityIncident.ReadWrite.All Read and write to incidents Microsoft Graph ThreatHunting.Read.All Run hunting queries
API Permission Description Microsoft Graph AuditLogsQuery.Read.All Read audit logs data from all services Microsoft Graph Content.Process.User Process content for data security, governance and compliance Microsoft Graph Files.ReadWrite.All Read and write files in all site collections Microsoft Graph InformationProtectionPolicy.Read.All Read all published labels and label policies for an organization. Microsoft Graph ProtectionScopes.Compute.All Compute Purview policies at tenant scope Microsoft Graph SecurityAlert.Read.All Read all security alerts Microsoft Graph SecurityAlert.ReadWrite.All Read and write to all security alerts Microsoft Graph SecurityIncident.Read.All Read all security incidents Microsoft Graph SecurityIncident.ReadWrite.All Read and write to all security incidents Microsoft Graph ThreatHunting.Read.All Run hunting queries
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Microsoft Purview Purview.DelegatedAccess Purview Delegated API Access
The signed-in user also needs a Purview collection role (Data Reader, Data Curator, Data Source Administrator, or Collection Admin depending on the tools used).
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Microsoft Graph DeviceManagementApps.Read.All Read Microsoft Intune apps Microsoft Graph DeviceManagementConfiguration.Read.All Read Microsoft Intune Device Configuration and Policies Microsoft Graph DeviceManagementManagedDevices.PrivilegedOperations.All Perform user-impacting remote actions on Microsoft Intune devices Microsoft Graph DeviceManagementManagedDevices.Read.All Read Microsoft Intune devices
API Permission Description Microsoft Graph DeviceManagementApps.Read.All Read Microsoft Intune apps Microsoft Graph DeviceManagementConfiguration.Read.All Read Microsoft Intune device configuration and policies Microsoft Graph DeviceManagementManagedDevices.PrivilegedOperations.All Perform user-impacting remote actions on Microsoft Intune devices Microsoft Graph DeviceManagementManagedDevices.Read.All Read Microsoft Intune devices
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Microsoft Graph Calendars.Read Read user calendars Microsoft Graph Calendars.Read.Shared Read user and shared calendars Microsoft Graph Calendars.ReadBasic Read basic details of user calendars Microsoft Graph Calendars.ReadWrite Have full access to user calendars
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Microsoft Graph Calendars.Read Read user calendars Microsoft Graph Calendars.Read.Shared Read user and shared calendars Microsoft Graph Calendars.ReadBasic Read basic details of user calendars Microsoft Graph Calendars.ReadWrite Have full access to user calendars Microsoft Graph Contacts.Read Read user contacts Microsoft Graph Mail.Read Read user mail Microsoft Graph Mail.ReadBasic Read user basic mail Microsoft Graph Mail.Send Send mail as a user Microsoft Graph People.Read Read users’ relevant people lists
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Microsoft Graph AccessReview.Read.All Read all access reviews that user can access Microsoft Graph AccessReview.ReadWrite.All Manage all access reviews that user can access Microsoft Graph EntitlementManagement.Read.All Read all entitlement management resources Microsoft Graph EntitlementManagement.ReadWrite.All Read and write entitlement management resources Microsoft Graph LifecycleWorkflows-Reports.Read.All Read all Lifecycle workflows reports Microsoft Graph LifecycleWorkflows-Workflow.Activate Run workflows on-demand in Lifecycle workflows Microsoft Graph LifecycleWorkflows-Workflow.ReadBasic.All List all workflows in Lifecycle workflows Microsoft Graph PrivilegedAssignmentSchedule.Read.AzureADGroup Read assignment schedules for access to Azure AD groups Microsoft Graph PrivilegedAssignmentSchedule.ReadWrite.AzureADGroup Read, create, and delete assignment schedules for access to Azure AD groups Microsoft Graph PrivilegedEligibilitySchedule.Read.AzureADGroup Read eligibility schedules for access to Azure AD groups Microsoft Graph PrivilegedEligibilitySchedule.ReadWrite.AzureADGroup Read, create, and delete eligibility schedules for access to Azure AD groups Microsoft Graph RoleAssignmentSchedule.Read.Directory Read all active role assignments for your company’s directory Microsoft Graph RoleAssignmentSchedule.ReadWrite.Directory Read, update, and delete all active role assignments for your company’s directory Microsoft Graph RoleEligibilitySchedule.Read.Directory Read all eligible role assignments for your company’s directory Microsoft Graph RoleEligibilitySchedule.ReadWrite.Directory Read, update, and delete all eligible role assignments for your company’s directory Microsoft Graph RoleManagement.Read.Directory Read directory RBAC settings
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Microsoft Graph Files.Read Read user files Microsoft Graph Files.ReadWrite Have full access to user files
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Microsoft Graph IdentityRiskyUser.Read.All Read identity risky user information Microsoft Graph IdentityRiskyUser.ReadWrite.All Read and write risky user information Microsoft Graph SecurityAlert.Read.All Read all security alerts Microsoft Graph SecurityAlert.ReadWrite.All Read and write to all security alerts Microsoft Graph SecurityEvents.Read.All Read your organization’s security events Microsoft Graph SecurityIncident.Read.All Read incidents Microsoft Graph SecurityIncident.ReadWrite.All Read and write to incidents Microsoft Graph ThreatHunting.Read.All Run hunting queries
API Permission Description Microsoft Graph IdentityRiskyUser.Read.All Read all identity risky user information Microsoft Graph IdentityRiskyUser.ReadWrite.All Read and write all risky user information Microsoft Graph SecurityAlert.Read.All Read all security alerts Microsoft Graph SecurityAlert.ReadWrite.All Read and write to all security alerts Microsoft Graph SecurityEvents.Read.All Read your organization’s security events Microsoft Graph SecurityIncident.Read.All Read all security incidents Microsoft Graph SecurityIncident.ReadWrite.All Read and write to all security incidents Microsoft Graph ThreatHunting.Read.All Run hunting queries
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Microsoft Graph Files.Read Read user files Microsoft Graph Files.Read.All Read all files that user can access Microsoft Graph Files.ReadWrite.All Have full access to all files user can access
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Microsoft Graph Files.Read Read user files Microsoft Graph Files.ReadWrite Have full access to user files Microsoft Graph Sites.Read.All Read items in all site collections Microsoft Graph Sites.ReadWrite.All Edit or delete items in all site collections
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Azure Service Management user_impersonation Access Azure Service Management as organization users (preview)
None. Azure Resource Manager has no application permissions; access comes from the Azure RBAC role below.
The signed-in user (or, in application mode, the app itself) also needs the Reader Azure RBAC role on the subscription or management group. Application mode needs no API permissions.
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Azure Service Management user_impersonation Access Azure Service Management as organization users (preview)
The signed-in user also needs the Security Reader Azure RBAC role, or Security Admin to update alerts.
API Permission Description Microsoft Graph User.Read Sign in and read user profile Microsoft Graph offline_access Maintain access to data you have given it access to Azure Service Management user_impersonation Access Azure Service Management as organization users (preview)
The signed-in user also needs the Microsoft Sentinel Reader Azure RBAC role, or Microsoft Sentinel Responder to update incidents and create bookmarks.