Skip to content

Azure permissions reference

This page is reference-only. Use it while configuring Azure RM for vScope or troubleshooting missing data.

Service areaPermission valueWhat it unlocks
AuditLogAuditLog.Read.AllRead audit log data
DeviceManagementAppsDeviceManagementApps.Read.AllIntune apps and assignments
DeviceManagementConfigurationDeviceManagementConfiguration.Read.AllIntune device configs and policies
DeviceManagementManagedDevicesDeviceManagementManagedDevices.Read.AllIntune-managed devices
DirectoryDirectory.Read.AllAzure AD / Entra directory data
GroupsGroup.Read.AllGroups and memberships
PolicyPolicy.Read.AllPolicy definitions
ReportsReports.Read.AllUsage reports
SharePointSites.Read.AllSharePoint site data
TeamsTeam.ReadBasic.AllBasic Teams info

Defender for Endpoint application permissions

Section titled “Defender for Endpoint application permissions”
Service areaPermission valueWhat it unlocks
AdvancedQueryAdvancedQuery.Read.AllAdvanced hunting queries
MachineMachine.Read.AllDefender device inventory
  • All listed Graph and Defender permissions require Grant admin consent after adding.
  • Assign Reader on every subscription you want inventoried (or an equivalent read role with no write privileges).
  • RBAC scope can be subscription, resource group, or resource; subscription-level is recommended to avoid gaps.