Tenet needs read-only access to your Microsoft 365
You're about to sign in with Microsoft. Here's exactly what Tenet is asking to read, and why - before Microsoft shows you its own permissions screen.
✓Read users and licensesso we can show you inactive accounts and license usage.
✓Read directory data (groups, org structure)so we can map users to groups and departments.
✓Read policy configurationso we can report on the security and compliance policies you have in place.
✓Read Conditional Access policiesso we can show which access policies are protecting your tenant.
✓Read managed device dataso we can report on device compliance and health.
✓Read Intune device configurationso we can show configuration profiles applied to devices.
✓Read Intune app management dataso we can report on managed application deployment.
✓Read Intune service configurationso we can report on your overall Intune setup.
✓Read security eventsso we can surface security alerts and incidents.
✓Read organization informationso we can display your tenant's basic profile and licensing.
✓Read audit and sign-in logsso we can show sign-in activity and directory changes.
✓Read risky user dataso we can flag accounts Microsoft has identified as at risk.
✓Read Microsoft 365 service healthso we can alert you to outages affecting your tenant.
✓Read authentication methodsso we can show MFA status per user.
✓Read usage reportsso we can show adoption and usage trends across Microsoft 365.
✓Read security alertsso we can surface threats detected across your tenant.
🛡️
Tenet is strictly read-only. We never create, change, or delete anything in your tenant - these permissions only let us read data to build your reports and dashboards.
You can review or revoke Tenet's access at any time from the Microsoft 365 admin center (Enterprise applications).