Skip to main content

Application Permissions for Entra ID Sync

The following permissions are required for the credential used by Threat Manager for Microsoft Entra ID Sync. See the Active Directory Sync Page topic for additional information about syncing the configured Microsoft Entra ID tenant(s) in Threat Manager.

Object TypeFunctionAccess Requirements
Administrative UnitRetrieve all administrative unitsAdministrativeUnit.Read.All
ApplicationRetrieve all applicationsApplication.Read.All
DeviceRetrieve all devicesDevice.Read.All
GroupRetrieve all groupsGroup.Read.All
Group MemberRetrieve all group membersGroupMember.Read.All
Identity Risky Service PrincipalRetrieve all risky service principalsIdentityRiskyServicePrincipal.Read.All
Identity Risky UserRetrieve all risky usersIdentityRiskyUser.Read.All
OrganizationRetrieve organization informationOrganization.Read.All
Role Assignment ScheduleRead and write role assignment schedules in the directoryRoleAssignmentSchedule.ReadWrite.Directory
Role Eligibility ScheduleRead and write role eligibility schedules in the directoryRoleEligibilitySchedule.ReadWrite.Directory
Role ManagementRetrieve all role management dataRoleManagement.Read.All
UserRetrieve all usersUser.Read.All