Check catalogue
On this page
Generated from the code. To refresh it, run this from v2/:
PYTHONPATH=. python scripts/gen_check_catalogue.py > docs/checks.md
54 checks, 27 data sources (collectors) and 33 detail reports.
A check reads only the data its collectors stored. When that data is missing, or the tenant's licence can't provide it, the check shows as not checked with the reason, instead of passing or failing.
Checks #
Accounts #
| Check | Reads data from | Licence note | Recommendation |
|---|---|---|---|
No inactive accountsstale_users |
users |
Sign-in activity needs Entra ID P1 | Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used (after checking with the client), then remove their licences. Inactive accounts are a common foothold for attackers. |
Admins #
| Check | Reads data from | Licence note | Recommendation |
|---|---|---|---|
Every admin has MFA registeredadmin_mfa |
admin_roles, mfa_registration |
Have each listed admin register a strong method (Authenticator or a FIDO2 key), or remove the role. Break-glass accounts should use FIDO2 keys kept offline. | |
Admins use phishing-resistant sign-in methodsadmin_phishing_resistant |
admin_roles, mfa_registration, users |
Have each listed admin register a passkey (in Microsoft Authenticator or on a security key) or Windows Hello for Business, then require the Phishing-resistant MFA authentication strength for admin roles in Conditional Access. Codes and push approvals can be relayed by a fake sign-in page; these can't. | |
Every admin is covered by an MFA policyadmins_ca_mfa |
admin_roles, conditional_access, users |
Make sure each admin is included in an enabled Conditional Access policy that requires MFA for all apps, and isn't excluded from it directly or through a group. Use a separate policy for break-glass accounts. | |
Between 2 and 4 Global Administratorsglobal_admin_count |
admin_roles |
Keep two to four Global Administrators: enough for a break-glass account, few enough to protect. Move day-to-day work to narrower roles such as User or Exchange Administrator. | |
No guests hold admin rolesguest_admins |
admin_roles |
Remove admin roles from guest accounts. If an external partner needs access, use GDAP or a member account in this tenant protected by MFA. | |
Apps with admin roles are reviewedservice_principal_admins |
admin_roles |
Check each app that holds a privileged directory role still needs it. A compromised app secret with an admin role bypasses MFA entirely. |
Apps #
| Check | Reads data from | Licence note | Recommendation |
|---|---|---|---|
App secrets and certificates are currentapp_credentials |
app_consents |
Renew credentials before they expire to avoid an outage, and delete app registrations whose credentials have all expired if nothing uses them any more. | |
Third-party apps hold only the access they needrisky_app_permissions |
app_consents |
Review each app with the client. Remove apps nobody recognises (Enterprise applications > Delete), and for the rest confirm the vendor and that it still needs mailbox or file access. | |
Users can't consent to apps on their ownuser_consent |
tenant_policies |
Set user consent to "Allow user consent for apps from verified publishers, for selected permissions" or turn it off and use the admin consent workflow. Consent phishing relies on this setting. |
Devices #
| Check | Reads data from | Licence note | Recommendation |
|---|---|---|---|
Managed devices check in with Intunedevice_checkin |
devices |
The tenant has no Intune licence, or Intune isn't readable | Find out whether each device is lost, replaced or broken. Retire devices that are gone; for devices still in use, restart the Intune Management Extension or re-enrol. |
Managed devices meet compliance policiesdevice_compliance |
devices |
The tenant has no Intune licence, or Intune isn't readable | Open each non-compliant device in Intune (Devices > Monitor > Noncompliant devices) to see which setting fails, fix it or retire the device, and block non-compliant devices with a Conditional Access policy that requires a compliant device. |
Company computers are encrypteddevice_encryption |
devices |
The tenant has no Intune licence, or Intune isn't readable | Turn on BitLocker (Windows) and FileVault (macOS) with an Intune disk encryption policy, with recovery keys escrowed to Entra ID, so a lost or stolen laptop doesn't expose the client's data. |
Joined computers are managed by Intuneintune_enrolled |
devices |
The tenant has no Intune licence, or Intune isn't readable | Enrol Entra-joined and hybrid-joined computers in Intune (automatic enrolment under Devices > Enrollment > Windows) so compliance, encryption and updates can be enforced on them. |
No old devices left in Entra IDstale_devices |
devices |
Disable, then after 30 days delete, device records that haven't signed in for 90 days (Entra admin center > Devices > All devices, filter by activity). Old records can still hold BitLocker keys and count toward device limits. | |
Windows computers still get security updatessupported_windows |
devices |
The tenant has no Intune licence, or Intune isn't readable | Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release (Intune: Windows feature updates policy). Replace hardware that can't run Windows 11, or buy Extended Security Updates as a stopgap. |
Email #
| Check | Reads data from | Licence note | Recommendation |
|---|---|---|---|
Automatic forwarding to outside addresses is offauto_forward_policy |
mailboxes |
The tenant has no Exchange Online licence | Set the outbound spam filter policy's automatic forwarding to Off (or Automatic, which Microsoft treats as Off), and allow forwarding only for named mailboxes with a separate policy. |
DKIM signing is on for every mail domaindkim_enabled |
domain_health |
Turn on DKIM for each domain in the Defender portal (Email authentication settings > DKIM), publishing the two selector CNAME records it shows. | |
Every domain enforces DMARCdmarc_policy |
domain_health |
Publish a DMARC record with a rua= reporting address, start at p=none to see who sends as the domain, then move to p=quarantine and p=reject. Without enforcement, spoofed mail from the domain is delivered. | |
No mail is forwarded outside the organisationexternal_forwarding |
inbox_rules, mailboxes, tenant_profile |
The tenant has no Exchange Online licence | Remove forwarding to outside addresses unless the client has a documented business reason. Forwarding is the most common way attackers keep reading a mailbox after a password reset. |
Mailbox auditing is onmailbox_auditing |
mailboxes |
The tenant has no Exchange Online licence | Turn mailbox auditing back on for the organisation (Set-OrganizationConfig -AuditDisabled $false). Without it there's no record of who read or deleted mail during an incident. |
Mail domains require encrypted delivery (MTA-STS)mta_sts |
domain_health |
Publish an MTA-STS policy so other mail servers only deliver to the domain over a verified, encrypted connection: a TXT record at _mta-sts. |
|
Shared mailboxes can't be signed in toshared_mailbox_signin |
mailboxes, users |
The tenant has no Exchange Online licence | Block sign-in for each shared mailbox's account (it doesn't need a password). An enabled shared mailbox account usually has no MFA and nobody watching it. |
SMTP AUTH is turned offsmtp_auth |
mailboxes |
The tenant has no Exchange Online licence | Turn off SMTP AUTH for the organisation and enable it only on the mailboxes of devices or apps that still need it, such as scanners. It accepts passwords without MFA. |
Every domain has a working SPF recordspf_record |
domain_health |
Publish one SPF record per domain ending in -all (or ~all while testing), e.g. "v=spf1 include:spf.protection.outlook.com -all". Domains that never send mail should publish "v=spf1 -all". | |
No inbox rules hide mailsuspicious_inbox_rules |
inbox_rules, mailboxes, tenant_profile |
The tenant has no Exchange Online licence | Check each rule with the mailbox owner. Rules that delete or bury messages about payments or security alerts are a sign of a compromised account: reset the password, revoke sessions and review sign-ins. |
Encrypted delivery failures are reported (TLS-RPT)tls_rpt |
domain_health |
Publish a TXT record at _smtp._tls. |
Groups #
| Check | Reads data from | Licence note | Recommendation |
|---|---|---|---|
Only chosen people can create teams and groupsgroup_creation |
groups |
Anyone can create teams and groups; limiting who can needs Entra ID P1 | Limit who can create teams and Microsoft 365 groups to a security group of people who will look after them (the Group.Unified directory setting, changed with Microsoft Graph PowerShell; needs Entra ID P1). Otherwise anyone can create a team, add guests to it and leave it behind. |
Unused groups and teams expiregroup_expiration |
groups |
Group expiration needs Entra ID P1 | Set a Microsoft 365 group expiration policy for all groups (Entra admin center > Groups > Expiration), for example 365 days. Groups in use renew automatically, owners are asked to renew the rest, and an expired group can be restored for 30 days. Needs Entra ID P1. |
Every team and Microsoft 365 group has an ownerownerless_groups |
groups |
Make an active person, ideally two, an owner of each listed team or group (Teams admin center or Microsoft 365 admin center > Teams & groups). Owners approve members and guests and renew the group; without one, nobody looks after its files and conversations. The ownerless group policy (Microsoft 365 admin center > Settings > Org settings > Microsoft 365 Groups) asks members to take over when the last owner leaves. |
Guests #
| Check | Reads data from | Licence note | Recommendation |
|---|---|---|---|
Only admins and members can invite guestsguest_invites |
tenant_policies |
Restrict guest invitations to admins and the Guest Inviter role, or at least to members, under External collaboration settings. | |
No old, unaccepted guest invitationspending_guests |
users |
Delete guest accounts whose invitation has gone unaccepted for 30 days; re-invite if still needed. |
Hybrid identity #
| Check | Reads data from | Licence note | Recommendation |
|---|---|---|---|
Admin accounts are cloud-onlycloud_only_admins |
admin_roles, directory_sync, users |
Give each admin a separate cloud-only account (for example on the .onmicrosoft.com domain) for their admin roles, and remove the roles from accounts synced from Active Directory. Otherwise anyone who takes over on-premises AD can reset those passwords and become an admin in Microsoft 365. | |
Directory sync is runningdirectory_sync_running |
directory_sync |
Check the Entra Connect server: that it is up, the Microsoft Azure AD Sync service is running and Synchronization Service Manager shows no errors. Until sync runs, accounts disabled or removed in Active Directory keep working in Microsoft 365. If the client has moved to cloud-only, turn directory sync off. | |
Password hash sync is onpassword_hash_sync |
directory_sync |
Turn on password hash synchronization in Entra Connect (Optional features), even when users sign in through federation or pass-through authentication. Entra ID can then detect leaked passwords, and sign-in can be switched to the cloud if the on-premises servers are down. |
Identity #
| Check | Reads data from | Licence note | Recommendation |
|---|---|---|---|
No unexpected changes to how domains sign indomain_federation_changed |
admin_activity |
Confirm with the client that each change was planned (for example, setting up AD FS or another identity provider). If it wasn't, an attacker with admin rights may have federated the domain to their own identity provider so they can sign in as any user without a password or MFA: switch the domain back to managed sign-in, remove unknown federation settings, reset admin credentials and review the audit log. | |
Legacy authentication is blockedlegacy_auth_blocked |
conditional_access |
Block legacy authentication (Exchange ActiveSync and other clients) with a Conditional Access policy for all users. Legacy protocols can't do MFA and are the most common password-spray target. | |
MFA is enforced for all usersmfa_enforced |
admin_roles, conditional_access, mfa_registration, users |
Create a Conditional Access policy requiring MFA for all users and all cloud apps, or turn on Security Defaults if the tenant has no Entra ID P1. Keep exclusions to break-glass accounts. | |
Nobody relies on a text or call as their only second factorphone_only_mfa |
admin_roles, mfa_registration, users |
Ask these people to set up the Microsoft Authenticator app (the registration campaign in the authentication methods policy prompts them at sign-in), then turn off text message and voice call sign-in, or keep them only as a backup. Texts and calls can be intercepted or moved to an attacker's SIM. | |
No risky sign-ins succeededrisky_sign_ins |
sign_ins |
Sign-in risk needs Entra ID P2; The sign-in log needs Entra ID P1 | Check each sign-in with the person. If they don't recognise it, reset their password, sign them out everywhere (revoke sessions), and check their MFA methods, inbox rules and app consents; then confirm the account compromised in Entra ID Protection. Add a Conditional Access policy that asks for MFA on medium and high sign-in risk. The Sign-in activity report lists every risky sign-in. |
No accounts are at risk in Entra ID Protectionrisky_users |
risky_users |
Risky users need Entra ID P2 | Check each account with the person. If they don't recognise recent sign-ins, reset the password, sign them out everywhere (revoke sessions), and check their MFA methods, inbox rules and app consents; then confirm the account compromised or dismiss the risk in Entra ID Protection. Add a Conditional Access policy that asks for a secure password change on high user risk. The Risky users report lists each account. |
Every active user has MFA registeredusers_mfa_registered |
mfa_registration, users |
Ask these users to register the Microsoft Authenticator app. Until they do, anyone with their password can register MFA in their place. |
Licences #
| Check | Reads data from | Licence note | Recommendation |
|---|---|---|---|
Every licence assignment workslicence_assignment_errors |
groups, tenant_profile, users |
Fix each failed licence from the group's Licenses page in the Entra admin center: buy more licences when there aren't enough, remove licences that conflict, and correct usage locations. The Licences and subscriptions report explains each error. | |
No licences on disabled accountslicensed_disabled |
users |
Remove licences from disabled accounts, or convert leavers' mailboxes to shared mailboxes (free up to 50 GB) before removing the licence. | |
No subscriptions are about to lapsesubscriptions_lapsing |
tenant_profile |
Renew subscriptions in their grace period, buy or cancel trials people use before they end, and move people off suspended subscriptions. Billing > Your products in the Microsoft 365 admin center (or Partner Center for subscriptions you sell) shows each one. | |
No paid licences sit unassignedunassigned_licences |
tenant_profile |
Reduce the subscription quantity at the next renewal, or assign the spare licences. |
Sharing #
| Check | Reads data from | Licence note | Recommendation |
|---|---|---|---|
No files are shared with anyone linksanyone_links |
shared_files, sharepoint_usage |
The tenant has no SharePoint licence | Remove anyone links that are no longer needed, and set the rest to view-only with an expiry date. The Shared files report lists each one. |
Files can't be shared with anonymous linkssharepoint_sharing |
tenant_policies |
Change SharePoint external sharing to "New and existing guests" so every external person signs in. If the client relies on Anyone links, set them to expire and to view-only. |
Storage #
| Check | Reads data from | Licence note | Recommendation |
|---|---|---|---|
SharePoint storage isn't nearly fullsharepoint_storage_space |
sharepoint_storage, tenant_profile |
Free up space before the tenant runs out, when people can no longer save files. The SharePoint storage report shows where the space goes and what to clear first; otherwise buy Office 365 Extra File Storage. |
Tenant settings #
| Check | Reads data from | Licence note | Recommendation |
|---|---|---|---|
Users have a way to get apps approvedadmin_consent_workflow |
tenant_policies |
Turn on admin consent requests (Entra admin center > Enterprise apps > Consent and permissions > Admin consent settings) and choose reviewers, so users blocked from consenting can ask instead of looking for a workaround. | |
Users can't register appsapp_registration |
tenant_policies |
Set "Users can register applications" to No (Entra admin center > Users > User settings) and give the Application Developer role to the people who need it. | |
People can't join the tenant just by verifying an email addressemail_verified_join |
tenant_policies |
Turn off email-verified sign-up with Microsoft Graph PowerShell (Update-MgPolicyAuthorizationPolicy -AllowEmailVerifiedUsersToJoinOrganization:$false), so accounts are only created by admins or invitation. | |
Guests have limited directory accessguest_access_level |
tenant_policies |
Set guest user access to "Guest users have limited access to properties and memberships of directory objects", or to the most restrictive option (Entra admin center > External Identities > External collaboration settings). | |
Users can't create new tenantstenant_creation |
tenant_policies |
Set "Restrict non-admin users from creating tenants" to Yes (Entra admin center > Users > User settings). A tenant a user creates sits outside the client's policies, with that user as its Global Administrator. |
Data sources (collectors) #
Each collector reads one area of a tenant and stores a snapshot. They run every night unless marked on demand.
| Key | Title | What it reads | Permissions |
|---|---|---|---|
admin_activity |
Admin activity | Admin role, Conditional Access, app credential, consent, domain and account changes from the directory audit log (30 days with Entra ID P1, otherwise 7). | AuditLog.Read.All |
admin_roles |
Admin roles | Who holds each directory role, active and PIM-eligible. | RoleManagement.Read.Directory |
app_consents |
Apps and consents | Third-party apps, the permissions granted to them, and app secrets or certificates expiring. | Application.Read.All, Directory.Read.All |
auth_methods_policy |
Sign-in methods policy | Which sign-in methods the tenant allows and for whom, the registration campaign and system-preferred MFA. | Policy.Read.All, Directory.Read.All |
conditional_access |
Conditional Access | Conditional Access policies and the Security Defaults setting. | Policy.Read.All |
connection |
Connection and permissions | Whether the app's permissions are granted in this tenant and it holds the Global Reader role. | Application.Read.All, RoleManagement.Read.Directory |
deleted_items |
Deleted users and groups | Users and Microsoft 365 groups in the Entra ID recycle bin, and how many days are left to restore each before Microsoft deletes it for good. | Directory.Read.All |
devices |
Devices | Devices registered or joined to Entra ID, and Intune compliance, encryption and check-in for managed devices (needs Intune). | Directory.Read.All, DeviceManagementManagedDevices.Read.All |
directory_sync |
Directory sync | Whether accounts are synced from on-premises Active Directory, when directory and password hash sync last ran, and how each domain signs in and how often its passwords expire. | Organization.Read.All, Directory.Read.All |
domain_health |
Email domains | SPF, DMARC, DKIM, MTA-STS and TLS-RPT for each verified domain, checked in public DNS. | none |
groups |
Groups and Teams | Every group, the owners, members and guests of each team and Microsoft 365 group, who can create them and whether unused ones expire. | Directory.Read.All |
inbox_rules |
Inbox rules | Every mailbox's inbox rules, to spot forwarding and rules that hide mail. | MailboxSettings.Read |
legacy_signins |
Legacy sign-ins | Sign-ins over SMTP AUTH, IMAP, POP and other basic-auth clients in the last 30 days (needs Entra ID P1). | AuditLog.Read.All |
m365_usage |
Microsoft 365 usage | Who used email, Teams, OneDrive, SharePoint and the Office apps in the last 30 days, from Microsoft's usage reports. | Reports.Read.All |
mailbox_usage |
Mailbox size | Size and item count of every mailbox, against its quota (needs Global Reader). | Exchange.ManageAsApp |
mailboxes |
Mailboxes | Mailboxes, forwarding, delegated access and organisation mail settings (needs Global Reader). | Exchange.ManageAsApp |
mfa_registration |
MFA registration | Which users have registered a second factor. | AuditLog.Read.All, UserAuthenticationMethod.Read.All |
per_user_mfa |
Per-user MFA | The per-user MFA setting on each member, for tenants without Entra ID P1. | Policy.Read.All |
risky_users |
Risky users | Accounts Entra ID Protection rates at risk or confirmed compromised, and those resolved in the last 90 days (needs Entra ID P2). | IdentityRiskyUser.Read.All |
secure_score |
Secure Score | Current Secure Score, per-control scores and up to 90 days of daily history. | SecurityEvents.Read.All |
shared_files |
Shared files | Every file and folder in SharePoint and OneDrive shared with anyone, the whole organisation, or people outside it. Needs the Sites.Read.All permission. | Sites.Read.All |
sharepoint_storage |
SharePoint storage | What fills each site's storage: libraries, folders, large and old files, version history and recycle bins. Needs the Sites.Read.All permission. | Sites.Read.All |
sharepoint_usage |
SharePoint and OneDrive usage | Every site and OneDrive with storage, activity and sharing link counts, from Microsoft's usage reports. | Reports.Read.All |
sign_ins |
Sign-in activity | Interactive sign-ins in the last 7 days, summarised by account, country, app and failure reason (needs Entra ID P1; sign-in risk needs P2). | AuditLog.Read.All |
tenant_policies |
Sharing and consent settings | Guest invitations, user consent to apps, default user permissions, admin consent requests, and SharePoint external sharing. | Policy.Read.All, SharePointTenantSettings.Read.All |
tenant_profile |
Tenant profile and licences | Organization details, verified domains, subscriptions with renewal dates and licence capabilities. | Organization.Read.All, Directory.Read.All |
users |
Users | Members and guests with licences (and whether each comes directly or from a group), password age and last sign-in (sign-in needs Entra ID P1). | User.Read.All, AuditLog.Read.All |
Detail reports #
Each one is a page at /tenants/<id>/data/<key> with an XLSX export.
| Key | Title | Description | Data from |
|---|---|---|---|
admin-activity |
Admin activity | Admin roles, Conditional Access, app credentials, consents, domains and account changes from the directory audit log, and who made them. | admin_activity |
admins |
Admins and roles | Every admin role holder with MFA, PIM and sign-in status, and a break-glass check. | admin_roles, conditional_access, mfa_registration, users |
apps |
Apps and consents | Third-party apps with access to the tenant, and app credential expiry. | app_consents |
auth-methods |
Passwords and sign-in methods | How people sign in and how strong that is: methods by strength, admins without phishing-resistant MFA, the methods policy, and password age and expiry. | admin_roles, auth_methods_policy, conditional_access, directory_sync, mfa_registration, users |
conditional-access |
Conditional Access coverage | Every policy in plain words, and which accounts each one actually covers. | admin_roles, conditional_access, users |
deleted-items |
Deleted users and groups | Users, teams and Microsoft 365 groups in the recycle bin, with the licences they held and the days left to restore each before Microsoft deletes it for good after 30 days. | deleted_items, tenant_profile |
devices |
Devices | Intune compliance, encryption and Windows support, and every Entra ID device record. | devices |
domains |
Email domains | SPF, DMARC, DKIM, MTA-STS and TLS-RPT for each of the tenant's domains, from public DNS. | domain_health |
group-membership |
Group membership | Who is in which team and Microsoft 365 group: each person's teams and groups, each group's members, and every membership in one table. | groups, users |
groups |
Groups and Teams | Who can create teams and groups, which have no owner, and the guests in each. | groups |
guests |
Guests and sharing | Who can invite and share externally, and every guest account. | tenant_policies, users |
hybrid |
Hybrid identity | Directory sync from on-premises AD, password hash sync, how each domain signs in, and admin accounts synced from AD. | admin_roles, directory_sync, users |
inactive |
Inactive accounts | Members and guests who haven't signed in for a long time, and old invitations. | admin_roles, tenant_profile, users |
inbox-rules |
Inbox rules | Rules that forward, delete or hide mail, and every rule in every mailbox. | inbox_rules, mailboxes |
legacy-auth |
Legacy sign-ins | Sign-ins with SMTP AUTH, IMAP, POP and other protocols that can't do MFA, and which mailboxes still allow them. | legacy_signins, mailboxes |
licence-rightsizing |
Licence right-sizing | People who could move to a cheaper licence, and services people are licensed for but don't use. | m365_usage, mailbox_usage, tenant_profile, users |
licences |
Licence waste | Paid licences nobody uses, in money, and the accounts holding them. | tenant_profile, users |
mailbox-holds |
Mailbox holds and archiving | Which mailboxes are on litigation hold or have an archive, leavers' mailboxes that aren't held, and large mailboxes that need an archive. | mailbox_usage, mailboxes, users |
mailbox-permissions |
Mailbox permissions | Who can open, send as or send on behalf of each mailbox, by person and by mailbox. | mailboxes, users |
mailbox-size |
Mailbox size | Every mailbox's size against its quota, largest share of quota first. | mailbox_usage |
mailboxes |
Mail forwarding | Every mailbox that sends mail on automatically, and the settings that allow it. | inbox_rules, mailboxes |
mfa |
MFA coverage | Who has set up MFA, who is required to use it, and where the two don't match. | admin_roles, conditional_access, mfa_registration, per_user_mfa, users |
onedrive |
OneDrive | Each person's OneDrive: storage, activity, sharing, and OneDrives of people who've left. | shared_files, sharepoint_usage, users |
risky-users |
Risky users | Accounts Entra ID Protection rates at risk or confirmed compromised, and the risk resolved recently (needs Entra ID P2). | risky_users, tenant_profile |
secure-score |
Secure Score trend | Secure Score over time, which controls changed, and where the points are. | secure_score |
shared-files |
Shared files | Every file and folder shared with anyone, people outside, or the whole organisation. | shared_files, sharepoint_usage |
shared-mailboxes |
Shared mailboxes | Shared, room and equipment mailboxes that can be signed in to, and who uses them. | mailbox_usage, mailboxes, users |
sharepoint |
SharePoint sites | Storage and growth, inactive sites, and which sites are shared outside. | sharepoint_usage |
sharepoint-storage |
SharePoint storage | What fills the tenant's SharePoint storage and what to clean up: sites, folders, large and old files, version history and recycle bins. | sharepoint_storage, sharepoint_usage, tenant_profile |
sign-ins |
Sign-in activity | Failed and successful sign-ins over the last week by account, country and app: password guessing, unusual countries, sign-ins without MFA and risky sign-ins. | sign_ins, tenant_profile |
subscriptions |
Licences and subscriptions | Every subscription with licences bought, assigned and available, its cost and renewal date, trials and lapsing subscriptions, and who has which licence, directly or by group. | groups, tenant_profile, users |
tenant-settings |
Tenant settings | What users and guests can do by default, and whether users can ask an admin to approve apps. | tenant_policies |
usage |
Microsoft 365 usage | Who actually uses email, Teams, OneDrive, SharePoint and the Office apps, and when each person was last active. | m365_usage |
Permissions #
Every application permission the app requests (all read-only) and the collectors that use it.
| Permission | API | Purpose | Used by |
|---|---|---|---|
Application.Read.All |
Microsoft Graph | App registrations, consents, secret expiry | app_consents, connection |
AuditLog.Read.All |
Microsoft Graph | Sign-in activity and audit logs | admin_activity, legacy_signins, mfa_registration, sign_ins, users |
DeviceManagementManagedDevices.Read.All |
Microsoft Graph | Intune device compliance | devices |
Directory.Read.All |
Microsoft Graph | Groups, roles, guests, domains | app_consents, auth_methods_policy, deleted_items, devices, directory_sync, groups, tenant_profile |
Exchange.ManageAsApp |
Exchange Online | Mailbox forwarding, permissions and mail settings (read-only cmdlets) | mailbox_usage, mailboxes |
IdentityRiskyUser.Read.All |
Microsoft Graph | Risky users (Entra ID P2) | risky_users |
MailboxSettings.Read |
Microsoft Graph | Inbox rules | inbox_rules |
Organization.Read.All |
Microsoft Graph | Tenant details and subscriptions | directory_sync, tenant_profile |
Policy.Read.All |
Microsoft Graph | Conditional Access and authorization policies | auth_methods_policy, conditional_access, per_user_mfa, tenant_policies |
Reports.Read.All |
Microsoft Graph | Usage and MFA registration reports | m365_usage, sharepoint_usage |
RoleManagement.Read.Directory |
Microsoft Graph | Admin role holders and PIM | admin_roles, connection |
SecurityEvents.Read.All |
Microsoft Graph | Secure Score | secure_score |
SharePointTenantSettings.Read.All |
Microsoft Graph | SharePoint sharing settings | tenant_policies |
Sites.Read.All |
Microsoft Graph | Which files are shared, and with whom (read-only) | shared_files, sharepoint_storage |
User.Read.All |
Microsoft Graph | Users, licences, password age | users |
UserAuthenticationMethod.Read.All |
Microsoft Graph | Registered MFA methods | mfa_registration |