One place to see every Microsoft Graph permission Torii needs for its Microsoft App Registration integrations.
Overview
This article lists the Microsoft Graph application permissions for the App Registration (app-only authentication) connection of these integrations:
- Microsoft Entra ID (App Registration) Integration
- Microsoft 365 (App Registration) Integration
- Microsoft Intune (App Registration) Integration
- Microsoft Teams (App Registration) Integration
Each permission is the smallest one Microsoft accepts for the calls Torii makes. When one bigger permission is already needed for another call in the same integration, Torii uses that one instead of adding a second.
Important
Data sync permissions are required. Workflow action permissions are optional - grant only the ones for the actions you plan to run.
Data sync permissions (required)
| Permission | Entra ID | Microsoft 365 | Intune | Teams | What Torii uses it for |
|---|---|---|---|---|---|
| User.Read.All | ✓ | ✓ | ✓ | ✓ | Read users |
| Directory.Read.All | ✓ | Read app consents, users’ group memberships, apps, directory roles and tenant info (also lists groups for the group actions) | |||
| AuditLog.Read.All | ✓ | Read sign-in logs for usage and last-activity data | |||
| LicenseAssignment.Read.All | ✓ | Read license (SKU) data | |||
| RoleManagement.Read.Directory | ✓ | ✓ | ✓ | Read directory role definitions and assignments | |
| Organization.Read.All | ✓ | ✓ | ✓ | Read organization and tenant information (Teams: also license data) | |
| Reports.Read.All | ✓ | Read Microsoft 365 usage and activity reports | |||
| DeviceManagementConfiguration.ReadWrite.All | ✓ | Create the discovered apps report | |||
| DeviceManagementConfiguration.Read.All | ✓ | Check the discovered apps report and download it | |||
| Group.Read.All | ✓ | Read Microsoft Teams-enabled groups and their members | |||
| TeamsAppInstallation.ReadForUser.All | ✓ | Read the apps installed for each user |
Workflow action permissions (optional)
| Permission | Entra ID | Microsoft 365 | Intune | Teams | What Torii uses it for |
|---|---|---|---|---|---|
| User.ReadWrite.All | ✓ | ✓ | ✓ | Delete users and assign/remove managers (Entra ID: also create/update users and change user type; Teams: also enable/disable accounts) | |
| Group.ReadWrite.All | ✓ | ✓ | Remove users from groups | ||
| User.EnableDisableAccount.All | ✓ | ✓ | Enable and disable user accounts | ||
| GroupMember.ReadWrite.All | ✓ | ✓ | Add users to groups | ||
| User.RevokeSessions.All | ✓ | ✓ | ✓ | Revoke user sign-in sessions | |
| Directory.Read.All | ✓ | Find the groups a user is in (Remove user from groups) | |||
| Group.ReadBasic.All | ✓ | List groups in the group actions | |||
| LicenseAssignment.ReadWrite.All | ✓ | Assign and remove licenses | |||
| User.Create | ✓ | ✓ | Create users | ||
| User.ReadUpdate.All | ✓ | ✓ | Update users, change user type, set alternate email | ||
| MailboxSettings.ReadWrite | ✓ | Create email forwarding rules, enable/disable automatic replies (out-of-office) | |||
| Calendars.ReadWrite | ✓ | Delete calendars and calendar events, remove calendar delegations | |||
| Files.ReadWrite.All | ✓ | Migrate OneDrive user files | |||
| DeviceManagementManagedDevices.ReadWrite.All | ✓ | Delete user devices and bypass activation lock | |||
| DeviceManagementManagedDevices.Read.All | ✓ | Find a user’s devices before a device action | |||
| DeviceManagementManagedDevices.PrivilegedOperations.All | ✓ | Remotely lock and wipe devices (Torii’s bypass activation lock action also checks for it) | |||
| TeamMember.ReadWrite.All | ✓ | Add and remove users from teams | |||
| TeamMember.Read.All | ✓ | Read team members before removing a user from a team | |||
| Channel.ReadBasic.All | ✓ | List team channels for bot messages | |||
| Team.ReadBasic.All | ✓ | Find the teams a user is in before removing them from teams |
How to grant the permissions
- In the Microsoft Entra admin center, go to Entra ID > App registrations and open the app you registered for Torii.
- Open API permissions > Add a permission > Microsoft Graph > Application permissions.
- Add the permissions from the tables above for each integration you connect.
- Select Grant admin consent and confirm.
Notes
- All permissions are Microsoft Graph application permissions and need tenant-wide admin consent.
- The Entra ID Exchange and runbook actions also need a Reader role on the Azure Automation account (Torii runbook), granted to the app registration's service principal. This is not a Graph permission, so it is not in the tables.
- Connecting with an administrator user (not App Registration)? This article does not apply - see the integration's Admin user article.
For any further questions, please contact Torii Support.