Consent once, read-only
An admin grants read consent to our shared Microsoft application. No app registration, no credential, nothing to deploy - and that grant is what activates the environment. These are the only four permissions requested:
- Organization.Read.All
- Directory.Read.All
- User.Read.All
- Policy.Read.All
Covers the basic tier of Inventory Overview and Identity - enough for users, licences, groups, domains, roles and security defaults.



