Check catalogue

On this page

Generated from the code. To refresh it, run this from v2/:

PYTHONPATH=. python scripts/gen_check_catalogue.py > docs/checks.md

54 checks, 27 data sources (collectors) and 33 detail reports.

A check reads only the data its collectors stored. When that data is missing, or the tenant's licence can't provide it, the check shows as not checked with the reason, instead of passing or failing.

Checks #

Accounts #

Check Reads data from Licence note Recommendation
No inactive accounts
stale_users
users Sign-in activity needs Entra ID P1 Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used (after checking with the client), then remove their licences. Inactive accounts are a common foothold for attackers.

Admins #

Check Reads data from Licence note Recommendation
Every admin has MFA registered
admin_mfa
admin_roles, mfa_registration Have each listed admin register a strong method (Authenticator or a FIDO2 key), or remove the role. Break-glass accounts should use FIDO2 keys kept offline.
Admins use phishing-resistant sign-in methods
admin_phishing_resistant
admin_roles, mfa_registration, users Have each listed admin register a passkey (in Microsoft Authenticator or on a security key) or Windows Hello for Business, then require the Phishing-resistant MFA authentication strength for admin roles in Conditional Access. Codes and push approvals can be relayed by a fake sign-in page; these can't.
Every admin is covered by an MFA policy
admins_ca_mfa
admin_roles, conditional_access, users Make sure each admin is included in an enabled Conditional Access policy that requires MFA for all apps, and isn't excluded from it directly or through a group. Use a separate policy for break-glass accounts.
Between 2 and 4 Global Administrators
global_admin_count
admin_roles Keep two to four Global Administrators: enough for a break-glass account, few enough to protect. Move day-to-day work to narrower roles such as User or Exchange Administrator.
No guests hold admin roles
guest_admins
admin_roles Remove admin roles from guest accounts. If an external partner needs access, use GDAP or a member account in this tenant protected by MFA.
Apps with admin roles are reviewed
service_principal_admins
admin_roles Check each app that holds a privileged directory role still needs it. A compromised app secret with an admin role bypasses MFA entirely.

Apps #

Check Reads data from Licence note Recommendation
App secrets and certificates are current
app_credentials
app_consents Renew credentials before they expire to avoid an outage, and delete app registrations whose credentials have all expired if nothing uses them any more.
Third-party apps hold only the access they need
risky_app_permissions
app_consents Review each app with the client. Remove apps nobody recognises (Enterprise applications > Delete), and for the rest confirm the vendor and that it still needs mailbox or file access.
Users can't consent to apps on their own
user_consent
tenant_policies Set user consent to "Allow user consent for apps from verified publishers, for selected permissions" or turn it off and use the admin consent workflow. Consent phishing relies on this setting.

Devices #

Check Reads data from Licence note Recommendation
Managed devices check in with Intune
device_checkin
devices The tenant has no Intune licence, or Intune isn't readable Find out whether each device is lost, replaced or broken. Retire devices that are gone; for devices still in use, restart the Intune Management Extension or re-enrol.
Managed devices meet compliance policies
device_compliance
devices The tenant has no Intune licence, or Intune isn't readable Open each non-compliant device in Intune (Devices > Monitor > Noncompliant devices) to see which setting fails, fix it or retire the device, and block non-compliant devices with a Conditional Access policy that requires a compliant device.
Company computers are encrypted
device_encryption
devices The tenant has no Intune licence, or Intune isn't readable Turn on BitLocker (Windows) and FileVault (macOS) with an Intune disk encryption policy, with recovery keys escrowed to Entra ID, so a lost or stolen laptop doesn't expose the client's data.
Joined computers are managed by Intune
intune_enrolled
devices The tenant has no Intune licence, or Intune isn't readable Enrol Entra-joined and hybrid-joined computers in Intune (automatic enrolment under Devices > Enrollment > Windows) so compliance, encryption and updates can be enforced on them.
No old devices left in Entra ID
stale_devices
devices Disable, then after 30 days delete, device records that haven't signed in for 90 days (Entra admin center > Devices > All devices, filter by activity). Old records can still hold BitLocker keys and count toward device limits.
Windows computers still get security updates
supported_windows
devices The tenant has no Intune licence, or Intune isn't readable Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release (Intune: Windows feature updates policy). Replace hardware that can't run Windows 11, or buy Extended Security Updates as a stopgap.

Email #

Check Reads data from Licence note Recommendation
Automatic forwarding to outside addresses is off
auto_forward_policy
mailboxes The tenant has no Exchange Online licence Set the outbound spam filter policy's automatic forwarding to Off (or Automatic, which Microsoft treats as Off), and allow forwarding only for named mailboxes with a separate policy.
DKIM signing is on for every mail domain
dkim_enabled
domain_health Turn on DKIM for each domain in the Defender portal (Email authentication settings > DKIM), publishing the two selector CNAME records it shows.
Every domain enforces DMARC
dmarc_policy
domain_health Publish a DMARC record with a rua= reporting address, start at p=none to see who sends as the domain, then move to p=quarantine and p=reject. Without enforcement, spoofed mail from the domain is delivered.
No mail is forwarded outside the organisation
external_forwarding
inbox_rules, mailboxes, tenant_profile The tenant has no Exchange Online licence Remove forwarding to outside addresses unless the client has a documented business reason. Forwarding is the most common way attackers keep reading a mailbox after a password reset.
Mailbox auditing is on
mailbox_auditing
mailboxes The tenant has no Exchange Online licence Turn mailbox auditing back on for the organisation (Set-OrganizationConfig -AuditDisabled $false). Without it there's no record of who read or deleted mail during an incident.
Mail domains require encrypted delivery (MTA-STS)
mta_sts
domain_health Publish an MTA-STS policy so other mail servers only deliver to the domain over a verified, encrypted connection: a TXT record at _mta-sts. ("v=STSv1; id=20260101") and a policy file at https://mta-sts./.well-known/mta-sts.txt listing the domain's MX hosts (for Microsoft 365, "mx: *.mail.protection.outlook.com"). Start with "mode: testing" and TLS-RPT reports, then switch to "mode: enforce" and change the id.
Shared mailboxes can't be signed in to
shared_mailbox_signin
mailboxes, users The tenant has no Exchange Online licence Block sign-in for each shared mailbox's account (it doesn't need a password). An enabled shared mailbox account usually has no MFA and nobody watching it.
SMTP AUTH is turned off
smtp_auth
mailboxes The tenant has no Exchange Online licence Turn off SMTP AUTH for the organisation and enable it only on the mailboxes of devices or apps that still need it, such as scanners. It accepts passwords without MFA.
Every domain has a working SPF record
spf_record
domain_health Publish one SPF record per domain ending in -all (or ~all while testing), e.g. "v=spf1 include:spf.protection.outlook.com -all". Domains that never send mail should publish "v=spf1 -all".
No inbox rules hide mail
suspicious_inbox_rules
inbox_rules, mailboxes, tenant_profile The tenant has no Exchange Online licence Check each rule with the mailbox owner. Rules that delete or bury messages about payments or security alerts are a sign of a compromised account: reset the password, revoke sessions and review sign-ins.
Encrypted delivery failures are reported (TLS-RPT)
tls_rpt
domain_health Publish a TXT record at _smtp._tls. such as "v=TLSRPTv1; rua=mailto:tls-reports@" (or a reporting service's address), so someone hears when other servers can't deliver mail encrypted, before and after MTA-STS is enforced.

Groups #

Check Reads data from Licence note Recommendation
Only chosen people can create teams and groups
group_creation
groups Anyone can create teams and groups; limiting who can needs Entra ID P1 Limit who can create teams and Microsoft 365 groups to a security group of people who will look after them (the Group.Unified directory setting, changed with Microsoft Graph PowerShell; needs Entra ID P1). Otherwise anyone can create a team, add guests to it and leave it behind.
Unused groups and teams expire
group_expiration
groups Group expiration needs Entra ID P1 Set a Microsoft 365 group expiration policy for all groups (Entra admin center > Groups > Expiration), for example 365 days. Groups in use renew automatically, owners are asked to renew the rest, and an expired group can be restored for 30 days. Needs Entra ID P1.
Every team and Microsoft 365 group has an owner
ownerless_groups
groups Make an active person, ideally two, an owner of each listed team or group (Teams admin center or Microsoft 365 admin center > Teams & groups). Owners approve members and guests and renew the group; without one, nobody looks after its files and conversations. The ownerless group policy (Microsoft 365 admin center > Settings > Org settings > Microsoft 365 Groups) asks members to take over when the last owner leaves.

Guests #

Check Reads data from Licence note Recommendation
Only admins and members can invite guests
guest_invites
tenant_policies Restrict guest invitations to admins and the Guest Inviter role, or at least to members, under External collaboration settings.
No old, unaccepted guest invitations
pending_guests
users Delete guest accounts whose invitation has gone unaccepted for 30 days; re-invite if still needed.

Hybrid identity #

Check Reads data from Licence note Recommendation
Admin accounts are cloud-only
cloud_only_admins
admin_roles, directory_sync, users Give each admin a separate cloud-only account (for example on the .onmicrosoft.com domain) for their admin roles, and remove the roles from accounts synced from Active Directory. Otherwise anyone who takes over on-premises AD can reset those passwords and become an admin in Microsoft 365.
Directory sync is running
directory_sync_running
directory_sync Check the Entra Connect server: that it is up, the Microsoft Azure AD Sync service is running and Synchronization Service Manager shows no errors. Until sync runs, accounts disabled or removed in Active Directory keep working in Microsoft 365. If the client has moved to cloud-only, turn directory sync off.
Password hash sync is on
password_hash_sync
directory_sync Turn on password hash synchronization in Entra Connect (Optional features), even when users sign in through federation or pass-through authentication. Entra ID can then detect leaked passwords, and sign-in can be switched to the cloud if the on-premises servers are down.

Identity #

Check Reads data from Licence note Recommendation
No unexpected changes to how domains sign in
domain_federation_changed
admin_activity Confirm with the client that each change was planned (for example, setting up AD FS or another identity provider). If it wasn't, an attacker with admin rights may have federated the domain to their own identity provider so they can sign in as any user without a password or MFA: switch the domain back to managed sign-in, remove unknown federation settings, reset admin credentials and review the audit log.
Legacy authentication is blocked
legacy_auth_blocked
conditional_access Block legacy authentication (Exchange ActiveSync and other clients) with a Conditional Access policy for all users. Legacy protocols can't do MFA and are the most common password-spray target.
MFA is enforced for all users
mfa_enforced
admin_roles, conditional_access, mfa_registration, users Create a Conditional Access policy requiring MFA for all users and all cloud apps, or turn on Security Defaults if the tenant has no Entra ID P1. Keep exclusions to break-glass accounts.
Nobody relies on a text or call as their only second factor
phone_only_mfa
admin_roles, mfa_registration, users Ask these people to set up the Microsoft Authenticator app (the registration campaign in the authentication methods policy prompts them at sign-in), then turn off text message and voice call sign-in, or keep them only as a backup. Texts and calls can be intercepted or moved to an attacker's SIM.
No risky sign-ins succeeded
risky_sign_ins
sign_ins Sign-in risk needs Entra ID P2; The sign-in log needs Entra ID P1 Check each sign-in with the person. If they don't recognise it, reset their password, sign them out everywhere (revoke sessions), and check their MFA methods, inbox rules and app consents; then confirm the account compromised in Entra ID Protection. Add a Conditional Access policy that asks for MFA on medium and high sign-in risk. The Sign-in activity report lists every risky sign-in.
No accounts are at risk in Entra ID Protection
risky_users
risky_users Risky users need Entra ID P2 Check each account with the person. If they don't recognise recent sign-ins, reset the password, sign them out everywhere (revoke sessions), and check their MFA methods, inbox rules and app consents; then confirm the account compromised or dismiss the risk in Entra ID Protection. Add a Conditional Access policy that asks for a secure password change on high user risk. The Risky users report lists each account.
Every active user has MFA registered
users_mfa_registered
mfa_registration, users Ask these users to register the Microsoft Authenticator app. Until they do, anyone with their password can register MFA in their place.

Licences #

Check Reads data from Licence note Recommendation
Every licence assignment works
licence_assignment_errors
groups, tenant_profile, users Fix each failed licence from the group's Licenses page in the Entra admin center: buy more licences when there aren't enough, remove licences that conflict, and correct usage locations. The Licences and subscriptions report explains each error.
No licences on disabled accounts
licensed_disabled
users Remove licences from disabled accounts, or convert leavers' mailboxes to shared mailboxes (free up to 50 GB) before removing the licence.
No subscriptions are about to lapse
subscriptions_lapsing
tenant_profile Renew subscriptions in their grace period, buy or cancel trials people use before they end, and move people off suspended subscriptions. Billing > Your products in the Microsoft 365 admin center (or Partner Center for subscriptions you sell) shows each one.
No paid licences sit unassigned
unassigned_licences
tenant_profile Reduce the subscription quantity at the next renewal, or assign the spare licences.

Sharing #

Check Reads data from Licence note Recommendation
No files are shared with anyone links
anyone_links
shared_files, sharepoint_usage The tenant has no SharePoint licence Remove anyone links that are no longer needed, and set the rest to view-only with an expiry date. The Shared files report lists each one.
Files can't be shared with anonymous links
sharepoint_sharing
tenant_policies Change SharePoint external sharing to "New and existing guests" so every external person signs in. If the client relies on Anyone links, set them to expire and to view-only.

Storage #

Check Reads data from Licence note Recommendation
SharePoint storage isn't nearly full
sharepoint_storage_space
sharepoint_storage, tenant_profile Free up space before the tenant runs out, when people can no longer save files. The SharePoint storage report shows where the space goes and what to clear first; otherwise buy Office 365 Extra File Storage.

Tenant settings #

Check Reads data from Licence note Recommendation
Users have a way to get apps approved
admin_consent_workflow
tenant_policies Turn on admin consent requests (Entra admin center > Enterprise apps > Consent and permissions > Admin consent settings) and choose reviewers, so users blocked from consenting can ask instead of looking for a workaround.
Users can't register apps
app_registration
tenant_policies Set "Users can register applications" to No (Entra admin center > Users > User settings) and give the Application Developer role to the people who need it.
People can't join the tenant just by verifying an email address
email_verified_join
tenant_policies Turn off email-verified sign-up with Microsoft Graph PowerShell (Update-MgPolicyAuthorizationPolicy -AllowEmailVerifiedUsersToJoinOrganization:$false), so accounts are only created by admins or invitation.
Guests have limited directory access
guest_access_level
tenant_policies Set guest user access to "Guest users have limited access to properties and memberships of directory objects", or to the most restrictive option (Entra admin center > External Identities > External collaboration settings).
Users can't create new tenants
tenant_creation
tenant_policies Set "Restrict non-admin users from creating tenants" to Yes (Entra admin center > Users > User settings). A tenant a user creates sits outside the client's policies, with that user as its Global Administrator.

Data sources (collectors) #

Each collector reads one area of a tenant and stores a snapshot. They run every night unless marked on demand.

Key Title What it reads Permissions
admin_activity Admin activity Admin role, Conditional Access, app credential, consent, domain and account changes from the directory audit log (30 days with Entra ID P1, otherwise 7). AuditLog.Read.All
admin_roles Admin roles Who holds each directory role, active and PIM-eligible. RoleManagement.Read.Directory
app_consents Apps and consents Third-party apps, the permissions granted to them, and app secrets or certificates expiring. Application.Read.All, Directory.Read.All
auth_methods_policy Sign-in methods policy Which sign-in methods the tenant allows and for whom, the registration campaign and system-preferred MFA. Policy.Read.All, Directory.Read.All
conditional_access Conditional Access Conditional Access policies and the Security Defaults setting. Policy.Read.All
connection Connection and permissions Whether the app's permissions are granted in this tenant and it holds the Global Reader role. Application.Read.All, RoleManagement.Read.Directory
deleted_items Deleted users and groups Users and Microsoft 365 groups in the Entra ID recycle bin, and how many days are left to restore each before Microsoft deletes it for good. Directory.Read.All
devices Devices Devices registered or joined to Entra ID, and Intune compliance, encryption and check-in for managed devices (needs Intune). Directory.Read.All, DeviceManagementManagedDevices.Read.All
directory_sync Directory sync Whether accounts are synced from on-premises Active Directory, when directory and password hash sync last ran, and how each domain signs in and how often its passwords expire. Organization.Read.All, Directory.Read.All
domain_health Email domains SPF, DMARC, DKIM, MTA-STS and TLS-RPT for each verified domain, checked in public DNS. none
groups Groups and Teams Every group, the owners, members and guests of each team and Microsoft 365 group, who can create them and whether unused ones expire. Directory.Read.All
inbox_rules Inbox rules Every mailbox's inbox rules, to spot forwarding and rules that hide mail. MailboxSettings.Read
legacy_signins Legacy sign-ins Sign-ins over SMTP AUTH, IMAP, POP and other basic-auth clients in the last 30 days (needs Entra ID P1). AuditLog.Read.All
m365_usage Microsoft 365 usage Who used email, Teams, OneDrive, SharePoint and the Office apps in the last 30 days, from Microsoft's usage reports. Reports.Read.All
mailbox_usage Mailbox size Size and item count of every mailbox, against its quota (needs Global Reader). Exchange.ManageAsApp
mailboxes Mailboxes Mailboxes, forwarding, delegated access and organisation mail settings (needs Global Reader). Exchange.ManageAsApp
mfa_registration MFA registration Which users have registered a second factor. AuditLog.Read.All, UserAuthenticationMethod.Read.All
per_user_mfa Per-user MFA The per-user MFA setting on each member, for tenants without Entra ID P1. Policy.Read.All
risky_users Risky users Accounts Entra ID Protection rates at risk or confirmed compromised, and those resolved in the last 90 days (needs Entra ID P2). IdentityRiskyUser.Read.All
secure_score Secure Score Current Secure Score, per-control scores and up to 90 days of daily history. SecurityEvents.Read.All
shared_files Shared files Every file and folder in SharePoint and OneDrive shared with anyone, the whole organisation, or people outside it. Needs the Sites.Read.All permission. Sites.Read.All
sharepoint_storage SharePoint storage What fills each site's storage: libraries, folders, large and old files, version history and recycle bins. Needs the Sites.Read.All permission. Sites.Read.All
sharepoint_usage SharePoint and OneDrive usage Every site and OneDrive with storage, activity and sharing link counts, from Microsoft's usage reports. Reports.Read.All
sign_ins Sign-in activity Interactive sign-ins in the last 7 days, summarised by account, country, app and failure reason (needs Entra ID P1; sign-in risk needs P2). AuditLog.Read.All
tenant_policies Sharing and consent settings Guest invitations, user consent to apps, default user permissions, admin consent requests, and SharePoint external sharing. Policy.Read.All, SharePointTenantSettings.Read.All
tenant_profile Tenant profile and licences Organization details, verified domains, subscriptions with renewal dates and licence capabilities. Organization.Read.All, Directory.Read.All
users Users Members and guests with licences (and whether each comes directly or from a group), password age and last sign-in (sign-in needs Entra ID P1). User.Read.All, AuditLog.Read.All

Detail reports #

Each one is a page at /tenants/<id>/data/<key> with an XLSX export.

Key Title Description Data from
admin-activity Admin activity Admin roles, Conditional Access, app credentials, consents, domains and account changes from the directory audit log, and who made them. admin_activity
admins Admins and roles Every admin role holder with MFA, PIM and sign-in status, and a break-glass check. admin_roles, conditional_access, mfa_registration, users
apps Apps and consents Third-party apps with access to the tenant, and app credential expiry. app_consents
auth-methods Passwords and sign-in methods How people sign in and how strong that is: methods by strength, admins without phishing-resistant MFA, the methods policy, and password age and expiry. admin_roles, auth_methods_policy, conditional_access, directory_sync, mfa_registration, users
conditional-access Conditional Access coverage Every policy in plain words, and which accounts each one actually covers. admin_roles, conditional_access, users
deleted-items Deleted users and groups Users, teams and Microsoft 365 groups in the recycle bin, with the licences they held and the days left to restore each before Microsoft deletes it for good after 30 days. deleted_items, tenant_profile
devices Devices Intune compliance, encryption and Windows support, and every Entra ID device record. devices
domains Email domains SPF, DMARC, DKIM, MTA-STS and TLS-RPT for each of the tenant's domains, from public DNS. domain_health
group-membership Group membership Who is in which team and Microsoft 365 group: each person's teams and groups, each group's members, and every membership in one table. groups, users
groups Groups and Teams Who can create teams and groups, which have no owner, and the guests in each. groups
guests Guests and sharing Who can invite and share externally, and every guest account. tenant_policies, users
hybrid Hybrid identity Directory sync from on-premises AD, password hash sync, how each domain signs in, and admin accounts synced from AD. admin_roles, directory_sync, users
inactive Inactive accounts Members and guests who haven't signed in for a long time, and old invitations. admin_roles, tenant_profile, users
inbox-rules Inbox rules Rules that forward, delete or hide mail, and every rule in every mailbox. inbox_rules, mailboxes
legacy-auth Legacy sign-ins Sign-ins with SMTP AUTH, IMAP, POP and other protocols that can't do MFA, and which mailboxes still allow them. legacy_signins, mailboxes
licence-rightsizing Licence right-sizing People who could move to a cheaper licence, and services people are licensed for but don't use. m365_usage, mailbox_usage, tenant_profile, users
licences Licence waste Paid licences nobody uses, in money, and the accounts holding them. tenant_profile, users
mailbox-holds Mailbox holds and archiving Which mailboxes are on litigation hold or have an archive, leavers' mailboxes that aren't held, and large mailboxes that need an archive. mailbox_usage, mailboxes, users
mailbox-permissions Mailbox permissions Who can open, send as or send on behalf of each mailbox, by person and by mailbox. mailboxes, users
mailbox-size Mailbox size Every mailbox's size against its quota, largest share of quota first. mailbox_usage
mailboxes Mail forwarding Every mailbox that sends mail on automatically, and the settings that allow it. inbox_rules, mailboxes
mfa MFA coverage Who has set up MFA, who is required to use it, and where the two don't match. admin_roles, conditional_access, mfa_registration, per_user_mfa, users
onedrive OneDrive Each person's OneDrive: storage, activity, sharing, and OneDrives of people who've left. shared_files, sharepoint_usage, users
risky-users Risky users Accounts Entra ID Protection rates at risk or confirmed compromised, and the risk resolved recently (needs Entra ID P2). risky_users, tenant_profile
secure-score Secure Score trend Secure Score over time, which controls changed, and where the points are. secure_score
shared-files Shared files Every file and folder shared with anyone, people outside, or the whole organisation. shared_files, sharepoint_usage
shared-mailboxes Shared mailboxes Shared, room and equipment mailboxes that can be signed in to, and who uses them. mailbox_usage, mailboxes, users
sharepoint SharePoint sites Storage and growth, inactive sites, and which sites are shared outside. sharepoint_usage
sharepoint-storage SharePoint storage What fills the tenant's SharePoint storage and what to clean up: sites, folders, large and old files, version history and recycle bins. sharepoint_storage, sharepoint_usage, tenant_profile
sign-ins Sign-in activity Failed and successful sign-ins over the last week by account, country and app: password guessing, unusual countries, sign-ins without MFA and risky sign-ins. sign_ins, tenant_profile
subscriptions Licences and subscriptions Every subscription with licences bought, assigned and available, its cost and renewal date, trials and lapsing subscriptions, and who has which licence, directly or by group. groups, tenant_profile, users
tenant-settings Tenant settings What users and guests can do by default, and whether users can ask an admin to approve apps. tenant_policies
usage Microsoft 365 usage Who actually uses email, Teams, OneDrive, SharePoint and the Office apps, and when each person was last active. m365_usage

Permissions #

Every application permission the app requests (all read-only) and the collectors that use it.

Permission API Purpose Used by
Application.Read.All Microsoft Graph App registrations, consents, secret expiry app_consents, connection
AuditLog.Read.All Microsoft Graph Sign-in activity and audit logs admin_activity, legacy_signins, mfa_registration, sign_ins, users
DeviceManagementManagedDevices.Read.All Microsoft Graph Intune device compliance devices
Directory.Read.All Microsoft Graph Groups, roles, guests, domains app_consents, auth_methods_policy, deleted_items, devices, directory_sync, groups, tenant_profile
Exchange.ManageAsApp Exchange Online Mailbox forwarding, permissions and mail settings (read-only cmdlets) mailbox_usage, mailboxes
IdentityRiskyUser.Read.All Microsoft Graph Risky users (Entra ID P2) risky_users
MailboxSettings.Read Microsoft Graph Inbox rules inbox_rules
Organization.Read.All Microsoft Graph Tenant details and subscriptions directory_sync, tenant_profile
Policy.Read.All Microsoft Graph Conditional Access and authorization policies auth_methods_policy, conditional_access, per_user_mfa, tenant_policies
Reports.Read.All Microsoft Graph Usage and MFA registration reports m365_usage, sharepoint_usage
RoleManagement.Read.Directory Microsoft Graph Admin role holders and PIM admin_roles, connection
SecurityEvents.Read.All Microsoft Graph Secure Score secure_score
SharePointTenantSettings.Read.All Microsoft Graph SharePoint sharing settings tenant_policies
Sites.Read.All Microsoft Graph Which files are shared, and with whom (read-only) shared_files, sharepoint_storage
User.Read.All Microsoft Graph Users, licences, password age users
UserAuthenticationMethod.Read.All Microsoft Graph Registered MFA methods mfa_registration