Skip to content

Griffin31 Connector Permission

When connecting Griffin31 to a Microsoft 365 tenant, specific permissions are required to enable access to necessary resources for security assessments.

Griffin31 operates without any write permissions in your Microsoft 365 tenant, ensuring it cannot alter any settings or configurations within the environment. Additionally, Griffin31 does not have access to any user data, such as files and emails stored within the tenant.

The platform is designed for read-only security assessments, focusing solely on identifying misconfigurations and vulnerabilities while maintaining strict adherence to data privacy and security protocols.


  • No Write Access: Cannot modify tenant settings or configurations
  • No User Data Access: Files and emails remain completely inaccessible
  • Read-Only Operations: Solely focused on security assessment and monitoring

Your organization’s data remains fully protected and inaccessible to Griffin31, ensuring complete compliance with data protection regulations.


PermissionPurposeSecurity Assessment Value
AppCatalog.Read.AllMonitor app catalogsEnsures no unapproved apps compromise security
Application.Read.AllReview all applicationsDetects potential vulnerabilities in integrated apps
AuditLog.Read.AllAccess audit log dataTracks changes and generates security audit trails
Channel.ReadBasic.AllRead Teams channel namesMonitors collaboration and prevents unauthorized channels
ChannelMember.Read.AllAccess Teams channel membersEnsures only authorized users access specific channels
ChannelSettings.Read.AllRead Teams channel settingsValidates proper configuration and permissions
DeviceManagementApps.Read.AllMonitor Intune appsEnsures compliant and secure applications on devices
DeviceManagementConfiguration.Read.AllReview Intune configurationsMonitors compliance and security configurations
Directory.Read.AllAccess directory dataMaintains overview of assets and assesses permissions
Domain.Read.AllRead domain informationMonitors domain configuration and security
Group.Read.AllAccess group dataReviews group memberships and access controls
IdentityProvider.Read.AllReview identity providersEvaluates security of identity sources
IdentityRiskEvent.Read.AllAccess identity risk eventsMonitors and assesses identity protection risks
IdentityRiskyServicePrincipal.Read.AllRead risky service principalsIdentifies potentially compromised service accounts
IdentityRiskyUser.Read.AllAccess risky user informationMonitors users flagged for security risks
InformationProtectionPolicy.Read.AllRead protection policiesAssesses data classification and protection policies
MailboxSettings.ReadAccess mailbox settingsMonitors email configurations and security
offline_access (Delegated)Maintain session continuityEnsures ongoing security assessment access
openid (Delegated)User authenticationRequired for Microsoft 365 resource access
Organization.Read.AllRead organization informationAssesses organizational structure and policies
OrgSettings-AppsAndServices.Read.AllAccess apps and services settingsMonitors application and service security
OrgSettings-Forms.Read.AllRead Forms settingsAssesses Microsoft Forms security configuration
Policy.Read.AllAccess organizational policiesEnsures security and compliance policy enforcement
profile (Delegated)View basic user profileRequired for authentication user information
RoleManagement.Read.AllRead role management dataAssesses role-based access control configurations
SharePointTenantSettings.Read.AllAccess SharePoint settingsMonitors secure configurations and file-sharing
Team.ReadBasic.AllList all teamsProvides Teams configuration overview
TeamMember.Read.AllRead team membersEnsures authorized user access to Teams
TeamSettings.Read.AllAccess Teams settingsEvaluates Microsoft Teams security settings
User.Read (Delegated)Sign in and read profileRequired for user authentication
User.Read.AllAccess full user profilesMonitors user activity and security
UserAuthenticationMethod.Read.AllRead authentication methodsAssesses authentication protocols like MFA
Exchange.ManageAsApp (Application)Access Exchange configurationsEnables Exchange Online security assessment

  • Directory.Read.All
  • User.Read.All
  • UserAuthenticationMethod.Read.All
  • IdentityRiskEvent.Read.All
  • IdentityRiskyUser.Read.All
  • IdentityRiskyServicePrincipal.Read.All
  • Application.Read.All
  • AppCatalog.Read.All
  • DeviceManagementApps.Read.All
  • DeviceManagementConfiguration.Read.All
  • Channel.ReadBasic.All
  • ChannelMember.Read.All
  • ChannelSettings.Read.All
  • Team.ReadBasic.All
  • TeamMember.Read.All
  • TeamSettings.Read.All
  • MailboxSettings.Read
  • Policy.Read.All
  • AuditLog.Read.All
  • InformationProtectionPolicy.Read.All
  • OrgSettings-AppsAndServices.Read.All
  • OrgSettings-Forms.Read.All

Key Takeaway: These permissions provide Griffin31 with the necessary visibility into Microsoft 365’s various components to monitor, assess, and ensure robust security practices across the tenant while maintaining strict read-only access and data privacy protection.