Required permissions for the M365 global administrator
Although a Global Administrator can authorize Block64 to access your M365 Data, all necessary permissions must be fulfilled to complete a full inventory if you opt for a permission level lower than Global Administrator. Here is a list of the minimum permissions required to conduct a comprehensive inventory of your M365 Data.
/me | Directory.Read.All | |
/users |
Directory.Read.All AuditLog.Read.All for signInActivity |
|
/groups | Directory.Read.All | |
/subscribedSkus | Directory.Read.All | |
/reports/getMailboxUsageDetail | Reports.Read.All | |
/security/secureScores | SecurityEvents.Read.All | |
/security/secureScoreControlProfiles | SecurityEvents.Read.All | |
/organization | Directory.Read.All | |
/reports/getOffice365ActivationsUserDetail | Reports.Read.All | |
/reports/getTeamsUserActivityUserDetail | Reports.Read.All | |
/reports/getSharePointActivityUserDetail | Reports.Read.All | |
/reports/getEmailActivityUserDetail | Reports.Read.All | |
/reports/getEmailActivityUserDetail | Reports.Read.All | |
/reports/getM365AppUserDetail | Reports.Read.All | |
/sites?search=* | Sites.Read.All | |
/sites/{site_id}/drive | Files.Read.All | |
/sites/{site_id}/drive/list/items | Files.Read.All | |
/sites/{site_id}/drive/items/{item_id}/permissions | Files.Read.All | |
/users/{user_id}/drives | Files.Read.All | |
/drives/{drive_id}/list/items |
Files.Read.All |
|
/drives/{drive_id}/items/{item_id}/permissions |
Files.Read.All |
|
/communications/callRecords/getPstnCalls |
CallRecords.Read.All |
|
/security/informationProtection/sensitivityLabels |
InformationProtectionPolicy.Read.All |