Views:

View a list of permissions that must be enabled within Microsoft Entra ID to facilitate integration with Trend Vision One.

Permission set
Permissions
Associated apps
Read directory data
  • Read directory data (Directory.Read.All)
  • Read all groups (Group.Read.All)
  • Read group memberships (GroupMember.Read.All)
  • Sign in and read user profile (User.Read)
  • Mobile Security
  • Phishing Simulation Assessment
  • Zero Trust Secure Access
Read user and device information, cloud app data, and activity data
  • Read directory data (Directory.Read.All)
  • Read all users' relevant people lists (People.Read.All)
  • Sign in and read user profile (User.Read)
  • Read all users' full profiles (User.Read.All)
  • Read items in all site collections (Sites.Read.All)
  • Read all groups (Group.Read.All)
  • Read all audit log data (AuditLog.Read.All)
  • Read identity risk event information (IdentityRiskEvent.Read.All)
  • Read all usage reports (Reports.Read.All)
  • Read your organization's security events (SecurityEvents.Read.All)
  • Read activity data for your organization (ActivityFeed.Read)
  • Read all user mailbox settings (MailboxSettings.Read)
  • Read organization information (Organization.Read.All)
  • Read all hidden memberships (Member.Read.Hidden)
  • Read threat assessment requests (ThreatAssessment.Read.All)
  • Read your organization's policies (Policy.Read.All)
  • Read users' authentication methods (UserAuthenticationMethod.Read.All)
  • Attack Surface Risk Management
  • Email Asset Inventory
  • Identity Security
Read directory data and perform account management actions
  • Read and write all users' full profiles (User.ReadWrite.All)
  • Manage all user identities (User.ManageIdentities.All)
  • Read and write directory data (Directory.ReadWrite.All)
  • Attack Surface Risk Management
  • Identity Security
  • Observed Attack Techniques
  • Search
  • Workbench
  • Zero Trust Secure Access
Read protected content and sensitivity label information
  • Read all protected content for this tenant (Content.SuperUser)
  • Read all published labels and label policies for an organization (InformationProtectionPolicy.Read.All)
  • Read organization information (Organization.Read.All)
  • Sign in and read user profile (User.Read)
  • Read all unified policies of the tenant (UnifiedPolicy.Tenant.Read?
  • Zero Trust Secure Access