Required API Permissions/Roles on a Microsoft Azure application

GG-Amitola
Tera Expert

In the DLP documentation

https://docs.servicenow.com/bundle/utah-security-management/page/product/dlp-microsoft/reference/get...

 

Under the heading 'Required API Permissions/Roles on a Microsoft Azure application' it states the following API Permissions/Roles are required on a MS Azure application and wondered if anyone knows the rationale behind all the Admin consent required, as there is concern over what that will allow what data to be accessed e.g. emails from the CEO, sensitive subject matter etc

 

You need the following API Permissions/Roles on a Microsoft Azure application to configure it on ServiceNow Microsoft DLP integration.

API Permission name Type Description Is Admin consent required?

Microsoft Graph APIFiles.Read.AllApplicationRead files in all site collections.
Files.ReadWrite.AllApplicationRead and write files in all site collections.
Mail.ReadApplicationRead mail in all mailboxes.
Mail.ReadBasic.AllApplicationRead basic mail in all mailboxes.
Mail.ReadWriteApplicationRead and write mail in all mailboxes.
Sites.Read.AllApplicationRead items in all site collections.
Sites.ReadWrite.AllApplicationRead and write items in all site collections
User.ReadDelegatedSign in and read user profile.x
Office 365 Management APIActivityFeed.ReadDlpApplicationRead DLP policy events including detected sensitive data.
     
0 REPLIES 0