📗
Required Application Permissions
API/Service | Permission Name | Type | Description | Admin Consent Required |
---|---|---|---|---|
Intune | get_device_compliance | Application | Get device state and compliance information from Microsoft Intune | Yes |
Log Analytics API | Data.Read | Application | Read Log Analytics data | Yes |
Microsoft Graph | AuditLog.Read.All | Application | Read all audit log data | Yes |
Microsoft Graph | Device.Read.All | Application | Read all devices | Yes |
Microsoft Graph | DeviceManagementConfiguration.Read.All | Application | Read Microsoft Intune device configuration and policies | Yes |
Microsoft Graph | DeviceManagementManagedDevices.Read.All | Application | Read Microsoft Intune devices | Yes |
Microsoft Graph | Directory.Read.All | Application | Read directory data | Yes |
Microsoft Graph | LicenseAssignment.Read.All | Application | Read all license assignments | Yes |
Microsoft Graph | Organization.Read.All | Application | Read organization information | Yes |
Microsoft Graph | Policy.Read.All | Application | Read your organization's policies | Yes |
Microsoft Graph | Policy.Read.DeviceConfiguration | Application | Read your organization's device configuration policies | Yes |
Microsoft Graph | SecurityActions.ReadWrite.All | Application | Read and update your organization's security actions | Yes |
Microsoft Graph | SecurityAlert.Read.All | Application | Read all security alerts | Yes |
Microsoft Graph | SecurityEvents.Read.All | Application | Read your organization's security events | Yes |
Microsoft Graph | SecurityIncident.Read.All | Application | Read all security incidents | Yes |
Microsoft Graph | SecurityIncident.ReadWrite.All | Application | Read and write to all security incidents | Yes |
Microsoft Graph | ThreatAssessment.Read.All | Application | Read threat assessment requests | Yes |
Microsoft Graph | ThreatHunting.Read.All | Application | Run hunting queries | Yes |
Microsoft Graph | ThreatIndicators.Read.All | Application | Read all threat indicators | Yes |
Microsoft Graph | ThreatIntelligence.Read.All | Application | Read all Threat Intelligence Information | Yes |
Microsoft Graph | User-PasswordProfile.ReadWrite.All | Application | Read and write all password profiles and reset user passwords | Yes |
Microsoft Graph | User.EnableDisableAccount.All | Application | Enable and disable user accounts | Yes |
Microsoft Graph | User.ReadWrite.All | Application | Read and write all users' full profiles | Yes |
Microsoft Graph | User.RevokeSessions.All | Application | Revoke all sign in sessions for a user | Yes |
Microsoft Graph | UserAuthenticationMethod.ReadWrite.All | Application | Read and write all users' authentication methods | Yes |
Windows Defender ATP | AdvancedQuery.Read.All | Application | Run advanced queries | Yes |
Windows Defender ATP | Alert.ReadWrite.All | Application | Read and write all alerts | Yes |
Windows Defender ATP | File.Read.All | Application | Read file profiles | Yes |
Windows Defender ATP | IntegrationConfiguration.ReadWrite.All | Application | Read and Write Integration settings | Yes |
Windows Defender ATP | Ip.Read.All | Application | Read IP address profiles | Yes |
Windows Defender ATP | Machine.Isolate | Application | Isolate machine | Yes |
Windows Defender ATP | Machine.Read.All | Application | Read all machine profiles | Yes |
Windows Defender ATP | Machine.ReadWrite.All | Application | Read and write all machine information | Yes |
Windows Defender ATP | Machine.Scan | Application | Scan machine | Yes |
Windows Defender ATP | Machine.StopAndQuarantine | Application | Stop and quarantine file | Yes |
Windows Defender ATP | RemediationTasks.Read.All | Application | Read all remediation tasks | Yes |
Windows Defender ATP | Score.Read.All | Application | Read Threat and Vulnerability Management score | Yes |
Windows Defender ATP | SecurityBaselinesAssessment.Read.All | Application | Read all security baselines assessment information | Yes |
Windows Defender ATP | SecurityConfiguration.Read.All | Application | Read all security configurations | Yes |
Windows Defender ATP | SecurityRecommendation.Read.All | Application | Read Threat and Vulnerability Management security recommendations | Yes |
Windows Defender ATP | Software.Read.All | Application | Read Threat and Vulnerability Management software information | Yes |
Windows Defender ATP | User.Read.All | Application | Read user profiles | Yes |
Windows Defender ATP | Vulnerability.Read.All | Application | Read Threat and Vulnerability Management vulnerability information | Yes |
Summary
Total Permissions Required: 37 permissions across 4 APIs/Services
- Intune: 1 permission
- Log Analytics API: 1 permission
- Microsoft Graph: 23 permissions
- Windows Defender ATP: 18 permissions
Admin Consent: Required for all permissions