Microsoft Graph API Permissions

Comprehensive list of Microsoft Graph API permissions required by Praxis Navigator for security monitoring, compliance tracking, and behavioral analytics.

37
Total Permissions
42
Total Endpoints
Application
Permission Type

Required Permissions

All permissions are of type "Application" and are marked as required for proper functionality.

Agreement.Read.All

Application Required v1.0.0
ID: ef4b5d93-3104-4f38-b3a8-b7a6c8fb7c3e

Used For

Monitor user agreement acceptances and policy acknowledgments to ensure compliance with organizational security policies.

API Endpoints (1)

/agreementAcceptances

Agreement acceptances and policy acknowledgments

AuditLog.Read.All

Application Required v1.0.0
ID: b0afded3-3588-46d8-8b3d-9842eff778da

Used For

Track sign-in activities, authentication events, and directory changes to identify potential security risks and unusual access patterns.

API Endpoints (2)

/auditLogs/signIns

Sign-in activities and authentication logs

/auditLogs/directoryAudits

Directory changes and audit events

AuthenticationContext.Read.All

Application Required v1.0.0
ID: a8edd6c7-6c0f-4c02-b0bb-8b2c4f6a1234

Used For

Monitor authentication context and conditional access policies to ensure proper security controls are in place.

API Endpoints (1)

/identity/conditionalAccess/authenticationContextClassReferences

Authentication context and conditional access

EventListener.Read.All

Application Required v1.0.0
ID: f1c7b6a5-4d3c-4e2f-8a9b-1c2d3e4f5a6b

Used For

Track authentication event listeners and triggers to monitor security-related authentication events.

API Endpoints (1)

/identity/authenticationEventListeners

Authentication event listeners and triggers

IdentityUserFlow.Read.All

Application Required v1.0.0
ID: 2e3f4a5b-6c7d-8e9f-0a1b-2c3d4e5f6a7b

Used For

Monitor identity user flows and authentication journeys to understand user authentication patterns.

API Endpoints (1)

/identity/userFlows

Identity user flows and authentication journeys

DeviceManagementApps.Read.All

Application Required v1.0.0
ID: 7ab1d382-f21e-4acd-a863-ba3e13f7da61

Used For

Access device management audit events to track mobile device and application security compliance.

API Endpoints (1)

/deviceManagement/auditEvents

Device management audit events

Directory.Read.All

Application Required v1.0.0
ID: 06da0dbc-49e2-44d2-8312-53f166ab848a

Used For

Read directory objects, user profiles, groups, and organizational structure to build comprehensive security culture reports.

API Endpoints (3)

/directoryObjects

Directory objects and organizational structure

/users

User profiles and directory information

/groups

Group information and memberships

DirectoryRecommendations.Read.All

Application Required v1.0.0
ID: ae73097b-cb2a-4447-b064-5d80f6093921

Used For

Access Azure AD security recommendations to provide actionable security improvement suggestions.

API Endpoints (1)

/directory/recommendations

Azure AD security recommendations

IdentityRiskEvent.Read.All

Application Required v1.0.0
ID: 6e472fd1-ad78-48da-a0f0-97ab2c6b769e

Used For

Monitor identity risk detections, risky sign-ins, and suspicious activities to identify potential security threats.

API Endpoints (2)

/identityProtection/riskDetections

Identity risk detections and events

/identityProtection/riskySignIns

Risky sign-in activities

IdentityRiskyUser.Read.All

Application Required v1.0.0
ID: dc5007c0-2d7d-4c42-879c-2dab87571379

Used For

Track users with risky behavior patterns to provide targeted security awareness training.

API Endpoints (1)

/identityProtection/riskyUsers

Users with risky behavior patterns

RiskPreventionProviders.Read.All

Application Required v1.0.0
ID: 9f9f8b2c-5d3e-4a1f-8c7b-6a9d8e7f5c4b

Used For

Monitor risk prevention providers and configurations to ensure comprehensive security coverage.

API Endpoints (1)

/identityProtection/riskPreventionProviders

Risk prevention providers and configurations

InformationProtectionConfig.Read.All

Application Required v1.0.0
ID: c79f8feb-a9db-4090-85f9-90d820caa0eb

Used For

Access information protection policies to monitor data classification and protection compliance.

API Endpoints (1)

/informationProtection/policy

Information protection policies and configurations

InformationProtectionPolicy.Read.All

Application Required v1.0.0
ID: 19dbc75e-c2e2-444c-a770-ec69d8559fc7

Used For

Monitor information protection labels and policies to track data security compliance.

API Endpoints (1)

/informationProtection/policy/labels

Information protection labels and policies

ThreatAssessment.Read.All

Application Required v1.0.0
ID: f8f035bb-2cce-47fb-8bf5-7baf3ecbee48

Used For

Access threat assessment requests and results to monitor security threat analysis activities.

API Endpoints (1)

/informationProtection/threatAssessmentRequests

Threat assessment requests and results

LearningAssignedCourse.Read.All

Application Required v1.0.0
ID: 1a1b2c3d-4e5f-6a7b-8c9d-0e1f2a3b4c5d

Used For

Track security training course assignments and completions to measure security awareness program effectiveness.

API Endpoints (1)

/employeeExperience/learningCourseActivities

Learning course assignments and completions

NetworkAccess-Reports.Read.All

Application Required v1.0.0
ID: 2b3c4d5e-6f7a-8b9c-0d1e-2f3a4b5c6d7e

Used For

Monitor network access reports and VPN usage to track remote access security patterns.

API Endpoints (1)

/networkAccess/reports

Network access reports and VPN usage

Organization.Read.All

Application Required v1.0.0
ID: 498476ce-e0fe-48b0-b801-37ba7e2685c6

Used For

Access organization information and tenant details to provide context for security culture assessments.

API Endpoints (1)

/organization

Organization information and tenant details

OrgContact.Read.All

Application Required v1.0.0
ID: e1a7a74e-5b36-4f56-9d65-8c39d1b96a4e

Used For

Monitor organizational contacts and external interactions for security risk assessment.

API Endpoints (1)

/contacts

Organizational contacts and external interactions

OrgSettings-Microsoft365Install.Read.All

Application Required v1.0.0
ID: 3c4d5e6f-7a8b-9c0d-1e2f-3a4b5c6d7e8f

Used For

Access Microsoft 365 service health and installation settings for comprehensive security monitoring.

API Endpoints (1)

/admin/serviceAnnouncement/healthOverviews

Microsoft 365 service health and installation settings

ReportSettings.Read.All

Application Required v1.0.0
ID: 4d5e6f7a-8b9c-0d1e-2f3a-4b5c6d7e8f9a

Used For

Monitor admin report settings to ensure proper security reporting configurations.

API Endpoints (1)

/admin/reportSettings

Admin report settings and configurations

Policy.Read.All

Application Required v1.0.0
ID: 246dd0d5-5bd0-4def-940b-0421030a5b68

Used For

Access organizational policies to ensure security culture alignment with corporate governance.

API Endpoints (1)

/policies

Organizational policies and configurations

ResourceSpecificPermissionGrant.Read.All

Application Required v1.0.0
ID: 5e6f7a8b-9c0d-1e2f-3a4b-5c6d7e8f9a0b

Used For

Monitor OAuth2 permission grants and delegations to track application access and potential security risks.

API Endpoints (1)

/oauth2PermissionGrants

OAuth2 permission grants and delegations

Insights-UserMetric.Read.All

Application Required v1.0.0
ID: 6f7a8b9c-0d1e-2f3a-4b5c-6d7e8f9a0b1c

Used For

Access user activity metrics including print jobs and Teams collaboration to understand user behavior patterns.

API Endpoints (2)

/reports/getUserArchivedPrintJobs

User archived print jobs and activity metrics

/reports/getTeamsUserActivityUserDetail

Teams user activity details and collaboration metrics

Reports.Read.All

Application Required v1.0.0
ID: 230c1aed-a721-4c5d-9cb4-a90514e508ef

Used For

Monitor authentication method registration details to track multi-factor authentication adoption.

API Endpoints (1)

/reports/authenticationMethods/userRegistrationDetails

Authentication method registration details

SecurityActions.Read.All

Application Required v1.0.0
ID: 7a8b9c0d-1e2f-3a4b-5c6d-7e8f9a0b1c2d

Used For

Track security actions and responses to monitor incident response effectiveness.

API Endpoints (1)

/security/securityActions

Security actions and responses

SecurityAlert.Read.All

Application Required v1.0.0
ID: bc423856-dc02-46b7-9b7d-1d7fdbba4d43

Used For

Monitor security alerts from Microsoft security services to provide comprehensive threat visibility.

API Endpoints (1)

/security/alerts

Security alerts from Microsoft security services

SecurityAnalyzedMessage.Read.All

Application Required v1.0.0
ID: 8b9c0d1e-2f3a-4b5c-6d7e-8f9a0b1c2d3e

Used For

Access analyzed email metadata and detection details to monitor phishing and email security threats.

API Endpoints (1)

/security/analyzedEmails

Analyzed email metadata and detection details

SecurityEvents.Read.All

Application Required v1.0.0
ID: bf394140-e372-4bf9-a898-299cfc7564e5

Used For

Monitor security events and threat detection data for comprehensive security monitoring.

API Endpoints (1)

/security/events

Security events and threat detection data

SecurityIdentitiesAccount.Read.All

Application Required v1.0.0
ID: 9c0d1e2f-3a4b-5c6d-7e8f-9a0b1c2d3e4f

Used For

Access security identity account information for user risk assessment.

API Endpoints (1)

/security/identities

Security identity account information

SecurityIdentitiesHealth.Read.All

Application Required v1.0.0
ID: 0d1e2f3a-4b5c-6d7e-8f9a-0b1c2d3e4f5a

Used For

Monitor identity security health issues and recommendations for proactive security improvements.

API Endpoints (1)

/security/identities/healthIssues

Identity security health issues and recommendations

SecurityIdentitiesUserActions.Read.All

Application Required v1.0.0
ID: 1e2f3a4b-5c6d-7e8f-9a0b-1c2d3e4f5a6b

Used For

Track identity security user actions and risk events for behavioral analysis.

API Endpoints (1)

/security/identities/userRiskEvents

Identity security user actions and risk events

SecurityIncident.Read.All

Application Required v1.0.0
ID: 45cc0394-e837-488b-a098-1918f48d186c

Used For

Monitor security incidents and investigation details to track organizational security posture.

API Endpoints (1)

/security/incidents

Security incidents and investigation details

ThreatHunting.Read.All

Application Required v1.0.0
ID: 2f3a4b5c-6d7e-8f9a-0b1c-2d3e4f5a6b7c

Used For

Access threat hunting queries and advanced analytics for proactive threat detection.

API Endpoints (1)

/security/runHuntingQuery

Threat hunting queries and advanced analytics

ThreatIndicators.Read.All

Application Required v1.0.0
ID: 197ee4e9-b993-4066-898f-d6aecc55125b

Used For

Monitor threat indicators and intelligence data to stay informed about current security threats.

API Endpoints (1)

/security/tiIndicators

Threat indicators and intelligence data

ThreatIntelligence.Read.All

Application Required v1.0.0
ID: 3a4b5c6d-7e8f-9a0b-1c2d-3e4f5a6b7c8d

Used For

Access threat intelligence information and indicators of compromise for enhanced security monitoring.

API Endpoints (1)

/security/threatIntelligence

Threat intelligence information and IOCs

ThreatSubmission.Read.All

Application Required v1.0.0
ID: 4b5c6d7e-8f9a-0b1c-2d3e-4f5a6b7c8d9e

Used For

Monitor user-reported threat submissions to track user security awareness and engagement.

API Endpoints (1)

/security/threatSubmission/emailThreats

User-reported threat submissions

VerifiedId-Profile.Read.All

Application Required v1.0.0
ID: 5c6d7e8f-9a0b-1c2d-3e4f-5a6b7c8d9e0f

Used For

Access verified ID profiles and credential information for identity verification monitoring.

API Endpoints (1)

/verifiableCredentials/authorities

Verified ID profiles and credential information

Permissions Manifest Information

Manifest Details

Version:
1.0.0
Last Updated:
December 2, 2025
Description:
Praxis Navigator Required Permissions Manifest

Integration Category

Name:
Microsoft Graph API
Type:
external_api
Description:
Permissions required for Microsoft Graph API access