Required permissions for the M365 global administrator
Although a Global Administrator can authorize Block64 to access your M365 Data, all necessary permissions must be fulfilled to complete a full inventory if you opt for a permission level lower than Global Administrator. Here is a list of the minimum permissions required to conduct a comprehensive inventory of your M365 Data.
| /me | Directory.Read.All | |
| /users |
Directory.Read.All AuditLog.Read.All for signInActivity |
|
| /groups | Directory.Read.All | |
| /subscribedSkus | Directory.Read.All | |
| /reports/getMailboxUsageDetail | Reports.Read.All | |
| /security/secureScores | SecurityEvents.Read.All | |
| /security/secureScoreControlProfiles | SecurityEvents.Read.All | |
| /organization | Directory.Read.All | |
| /reports/getOffice365ActivationsUserDetail | Reports.Read.All | |
| /reports/getTeamsUserActivityUserDetail | Reports.Read.All | |
| /reports/getSharePointActivityUserDetail | Reports.Read.All | |
| /reports/getEmailActivityUserDetail | Reports.Read.All | |
| /reports/getEmailActivityUserDetail | Reports.Read.All | |
| /reports/getM365AppUserDetail | Reports.Read.All | |
| /sites?search=* | Sites.Read.All | |
| /sites/{site_id}/drive | Files.Read.All | |
| /sites/{site_id}/drive/list/items | Files.Read.All | |
| /sites/{site_id}/drive/items/{item_id}/permissions | Files.Read.All | |
| /users/{user_id}/drives | Files.Read.All | |
| /drives/{drive_id}/list/items |
Files.Read.All |
|
| /drives/{drive_id}/items/{item_id}/permissions |
Files.Read.All |
|
| /communications/callRecords/getPstnCalls |
CallRecords.Read.All |
|
| /security/informationProtection/sensitivityLabels |
InformationProtectionPolicy.Read.All |