CyberProva transparency
Microsoft 365 permissions and removing access
Understand every documented Microsoft Graph assessment permission, what CyberProva reads and how your administrator can revoke access.
Read-only assessment access
CyberProva's assessment connection uses Microsoft Graph application permissions authorised by your Microsoft tenant administrator. It does not request Graph write permissions to change your tenant configuration.
- Read-only access still exposes sensitive directory and security information. Review each permission before consenting.
- The table below describes 15 permissions supported by the assessment collectors. It is not a claim that all 15 are requested or granted in every deployment. Microsoft sign-in is a separate authentication flow.
- The production assessment app registration was checked on 7 October 2026: it requests the six core permissions below, plus Directory.Read.All, SharePointTenantSettings.Read.All, IdentityRiskEvent.Read.All and IdentityRiskyUser.Read.All. It declares no Graph write permissions.
- The other five supported advanced permissions are not currently declared by that production registration. Checks needing them can report access unavailable; adding them would require a separate application change and customer administrator consent.
- Granted access in your own tenant can differ from a registration's declared permission list. Review the actual consent screen and enterprise-application grants. Missing access or licences is reported in affected findings.
Remove CyberProva's Microsoft 365 access
A Microsoft tenant administrator can revoke the assessment application's granted permissions in Microsoft Entra. Find the CyberProva assessment enterprise application by its application ID from the connection/consent screen, especially if its display name differs from the sign-in application.
- Open the Microsoft Entra admin centre and select Enterprise applications, then the assessment application.
- Open Permissions and review Admin consent. Revoke the granted permissions using Microsoft's documented procedure; deleting the enterprise application also removes its service principal and grants.
- Do not rely only on blocking user sign-in: the assessment uses app-only access.
- Already-issued access tokens can remain valid until they expire. A future connection may require consent again.
- Revoking access stops future authorised reads; it does not delete previously stored results, uploaded evidence or cancel your subscription.
Assessment permission details
All permissions below permit reads within their Microsoft-defined scope. None grants permission to modify Microsoft 365 configuration. Read access can be wider than the particular fields CyberProva uses; review Microsoft's permission reference before granting consent.
Microsoft Graph permission reference · Microsoft's permission revocation instructions