How can we help?

Microsoft Graph Permissions for Each Microsoft App Registration Integration

Netanel Hugi
Netanel Hugi
  • Updated
Torii SMP
Torii Identity

One place to see every Microsoft Graph permission Torii needs for its Microsoft App Registration integrations.

Overview

This article lists the Microsoft Graph application permissions for the App Registration (app-only authentication) connection of these integrations:

Each permission is the smallest one Microsoft accepts for the calls Torii makes. When one bigger permission is already needed for another call in the same integration, Torii uses that one instead of adding a second.

Important
Data sync permissions are required. Workflow action permissions are optional - grant only the ones for the actions you plan to run.

Data sync permissions (required)

Permission Entra ID Microsoft 365 Intune Teams What Torii uses it for
User.Read.All ✓ ✓ ✓ ✓ Read users
Directory.Read.All ✓ Read app consents, users’ group memberships, apps, directory roles and tenant info (also lists groups for the group actions)
AuditLog.Read.All ✓ Read sign-in logs for usage and last-activity data
LicenseAssignment.Read.All ✓ Read license (SKU) data
RoleManagement.Read.Directory ✓ ✓ ✓ Read directory role definitions and assignments
Organization.Read.All ✓ ✓ ✓ Read organization and tenant information (Teams: also license data)
Reports.Read.All ✓ Read Microsoft 365 usage and activity reports
DeviceManagementConfiguration.ReadWrite.All ✓ Create the discovered apps report
DeviceManagementConfiguration.Read.All ✓ Check the discovered apps report and download it
Group.Read.All ✓ Read Microsoft Teams-enabled groups and their members
TeamsAppInstallation.ReadForUser.All ✓ Read the apps installed for each user

Workflow action permissions (optional)

Permission Entra ID Microsoft 365 Intune Teams What Torii uses it for
User.ReadWrite.All ✓ ✓ ✓ Delete users and assign/remove managers (Entra ID: also create/update users and change user type; Teams: also enable/disable accounts)
Group.ReadWrite.All ✓ ✓ Remove users from groups
User.EnableDisableAccount.All ✓ ✓ Enable and disable user accounts
GroupMember.ReadWrite.All ✓ ✓ Add users to groups
User.RevokeSessions.All ✓ ✓ ✓ Revoke user sign-in sessions
Directory.Read.All ✓ Find the groups a user is in (Remove user from groups)
Group.ReadBasic.All ✓ List groups in the group actions
LicenseAssignment.ReadWrite.All ✓ Assign and remove licenses
User.Create ✓ ✓ Create users
User.ReadUpdate.All ✓ ✓ Update users, change user type, set alternate email
MailboxSettings.ReadWrite ✓ Create email forwarding rules, enable/disable automatic replies (out-of-office)
Calendars.ReadWrite ✓ Delete calendars and calendar events, remove calendar delegations
Files.ReadWrite.All ✓ Migrate OneDrive user files
DeviceManagementManagedDevices.ReadWrite.All ✓ Delete user devices and bypass activation lock
DeviceManagementManagedDevices.Read.All ✓ Find a user’s devices before a device action
DeviceManagementManagedDevices.PrivilegedOperations.All ✓ Remotely lock and wipe devices (Torii’s bypass activation lock action also checks for it)
TeamMember.ReadWrite.All ✓ Add and remove users from teams
TeamMember.Read.All ✓ Read team members before removing a user from a team
Channel.ReadBasic.All ✓ List team channels for bot messages
Team.ReadBasic.All ✓ Find the teams a user is in before removing them from teams

How to grant the permissions

  1. In the Microsoft Entra admin center, go to Entra ID > App registrations and open the app you registered for Torii.
  2. Open API permissions > Add a permission > Microsoft Graph > Application permissions.
  3. Add the permissions from the tables above for each integration you connect.
  4. Select Grant admin consent and confirm.

Notes

  • All permissions are Microsoft Graph application permissions and need tenant-wide admin consent.
  • The Entra ID Exchange and runbook actions also need a Reader role on the Azure Automation account (Torii runbook), granted to the app registration's service principal. This is not a Graph permission, so it is not in the tables.
  • Connecting with an administrator user (not App Registration)? This article does not apply - see the integration's Admin user article.


For any further questions, please contact Torii Support.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request