CyberProva transparency

Microsoft 365 permissions and removing access

Understand every documented Microsoft Graph assessment permission, what CyberProva reads and how your administrator can revoke access.

Read-only assessment access

CyberProva's assessment connection uses Microsoft Graph application permissions authorised by your Microsoft tenant administrator. It does not request Graph write permissions to change your tenant configuration.

  • Read-only access still exposes sensitive directory and security information. Review each permission before consenting.
  • The table below describes 15 permissions supported by the assessment collectors. It is not a claim that all 15 are requested or granted in every deployment. Microsoft sign-in is a separate authentication flow.
  • The production assessment app registration was checked on 7 October 2026: it requests the six core permissions below, plus Directory.Read.All, SharePointTenantSettings.Read.All, IdentityRiskEvent.Read.All and IdentityRiskyUser.Read.All. It declares no Graph write permissions.
  • The other five supported advanced permissions are not currently declared by that production registration. Checks needing them can report access unavailable; adding them would require a separate application change and customer administrator consent.
  • Granted access in your own tenant can differ from a registration's declared permission list. Review the actual consent screen and enterprise-application grants. Missing access or licences is reported in affected findings.

Remove CyberProva's Microsoft 365 access

A Microsoft tenant administrator can revoke the assessment application's granted permissions in Microsoft Entra. Find the CyberProva assessment enterprise application by its application ID from the connection/consent screen, especially if its display name differs from the sign-in application.

  • Open the Microsoft Entra admin centre and select Enterprise applications, then the assessment application.
  • Open Permissions and review Admin consent. Revoke the granted permissions using Microsoft's documented procedure; deleting the enterprise application also removes its service principal and grants.
  • Do not rely only on blocking user sign-in: the assessment uses app-only access.
  • Already-issued access tokens can remain valid until they expire. A future connection may require consent again.
  • Revoking access stops future authorised reads; it does not delete previously stored results, uploaded evidence or cancel your subscription.

Assessment permission details

All permissions below permit reads within their Microsoft-defined scope. None grants permission to modify Microsoft 365 configuration. Read access can be wider than the particular fields CyberProva uses; review Microsoft's permission reference before granting consent.

Supported Microsoft Graph application permissions — actual requested and granted permissions depend on the deployment and consent
PermissionWhy CyberProva uses itAssessment scope
SecurityEvents.Read.AllRead Microsoft Secure Score and its available security information.Core assessment
User.Read.AllRead user inventory, account state and available sign-in activity.Core assessment
RoleManagement.Read.DirectoryRead directory role assignments to identify privileged principals.Core assessment
Application.Read.AllRead application and service-principal inventory, owners and credential expiry metadata; not secret values.Core assessment
Policy.Read.AllRead Conditional Access, authentication strengths, security defaults, consent and cross-tenant policies.Core assessment
AuditLog.Read.AllRead directory audit events, sign-in records and authentication-method registration reports.Core assessment
LicenseAssignment.Read.AllRead subscribed service plans to identify licensing prerequisites.Additional advanced checks
RoleAssignmentSchedule.Read.DirectoryRead scheduled role assignment instances for the privileged-access review.Additional advanced checks
DeviceManagementManagedDevices.Read.AllRead Intune managed-device inventory, encryption and compliance state.Additional advanced checks
DeviceManagementConfiguration.Read.AllRead Intune compliance and configuration policies.Additional advanced checks
DeviceLocalCredential.ReadBasic.AllRead device local-credential backup metadata; not LAPS passwords.Additional advanced checks
Directory.Read.AllRead directory group settings for the Entra Password Protection review. This is a broad directory read permission.Additional advanced checks
SharePointTenantSettings.Read.AllRead tenant-wide SharePoint and OneDrive sharing and link settings.Additional advanced checks
IdentityRiskEvent.Read.AllRead Microsoft's leaked-credential detections using selected identifiers and risk fields; requires Entra ID P2.Additional advanced checks
IdentityRiskyUser.Read.AllRead current account risk state for the leaked-credential check; requires Entra ID P2.Additional advanced checks

Microsoft Graph permission reference · Microsoft's permission revocation instructions