PlatformInfraSaasM365

  1. In the navigation sidebar, select API permissions.

API permissions

By default, Microsoft grants your new application User.Read permission for Microsoft Graph. It's not required for Mondoo, so you can remove it.

  1. Select + Add a permission.

Add permission in Azure

  1. From the list of Commonly used Microsoft APIs, select Microsoft Graph.

API permissions

  1. Because Mondoo acts as a service, select Application permissions.

  2. Select expand all to see all permissions. Then select the required API permissions:

Microsoft GraphTypeDescription
IdentityProvider.Read.AllApplicationRead identity providers
Policy.Read.AllApplicationRead your organization's policies
Policy.Read.ConditionalAccessApplicationRead your organization's conditional access policies
Policy.Read.PermissionGrantApplicationRead consent and permission grant policies
SecurityActions.Read.AllApplicationRead your organization's security actions
SecurityEvents.Read.AllApplicationRead your organization's security events
DeviceManagementConfiguration.Read.AllApplicationRead Microsoft Intune device configuration and policies
AuditLog.Read.AllApplicationRead all audit log data
Directory.Read.AllApplicationRead directory data
  1. Select the Add permissions button.

  2. Grant Mondoo read permissions for SharePoint.

    SharePoint APIsTypeDescription
    Sites.FullControl.AllApplicationHave full control of all site collections
  3. Select the Add permissions button.

  4. Grant Mondoo read permissions for Office 365 Exchange Online. You need to search in APIs my organization uses.

    Office 365 Exchange OnlineTypeDescription
    Exchange.ManageAsAppApplicationRun Exchange Online commands as if Mondoo was an administrator account
  5. To complete the process, select Grant admin consent for (your tenant name) and select the Yes button to confirm.