Microsoft 365 security assessment permissions
What Vitals can access, what it keeps, and how to take it back.
The reference for your IT provider, security lead or data-protection officer. The short version: read-only permissions granted through Microsoft, nothing installed, contents never read, and access you can revoke in one click.
The 11 Microsoft Graph permissions Vitals requests
The application permissions the consent screen shows, and what each is used for. Every one is a read permission. If some are not granted, the assessment still runs and marks what it could not read as not assessed.
Vitals reads metadata and properties, not document or message contents. Files.Read.All and Sites.Read.All can technically permit access to file content, but the Vitals scan uses them only to read properties such as sharing and site information. Vitals requests no email-body, Teams chat or message-content permissions.
| Permission | Used for |
|---|---|
| Sites.Read.All | Which SharePoint sites exist, how big they are, when they were last active, and which have no owner. |
| Files.Read.All | File properties in the largest sites: who each file is shared with, whether it carries a label, when it changed, and a content hash for duplicate detection. Never the file itself. |
| Directory.Read.All | Users, guests, groups, administrators, licences and the subscriptions they come from. |
| SensitivityLabel.Read | The label scheme the tenant has published, so unlabelled can be told from labelled. |
| DeviceManagementManagedDevices.Read.All | Devices enrolled in Intune, whether they meet the tenant’s own policy, and when they last checked in. |
| Policy.Read.All | Conditional Access policies and their state; security defaults; the authentication methods policy; sharing settings. |
| Reports.Read.All | Microsoft’s own usage and registration reports — who is active, who can complete a multi-factor prompt. Aggregated in the report. |
| SecurityEvents.Read.All | Microsoft Secure Score and the controls behind it, so the report can put Microsoft’s number beside ours. |
| SharePointTenantSettings.Read.All | The tenant-wide sharing defaults: whether anonymous links are allowed, what a Share button offers first, whether links expire. |
| MailboxSettings.Read | Mailbox rules — the ones that forward or delete mail automatically. The rules, never the messages. |
| AuditLog.Read.All | Thirty days of the directory audit log for one question: which accounts acquired a new sign-in method, and who added it. |
This list is Schedule 1 of the Data Processing Agreement and matches the application registration, which carries Microsoft’s verified-publisher mark.
How the scan runs
You pay and forward one approval link to whoever administers your Microsoft 365. A Global Administrator approves the application through Microsoft’s consent screen. Vitals reads the tenant through Microsoft Graph, in memory, for the length of the scan, and the report is delivered by a private link within three working days. Nothing is installed in the tenant, no agent runs afterwards, and nobody at Innova Group signs in to anything.
What is kept, and for how long
- Your report
- Thirty days, behind a private link that then expires. Save a copy to keep it.
- Your name and email
- Thirty days, for delivery and support, then removed automatically.
- Scores, counts and configuration states
- Retained so a later scan can report what changed. Nothing that identifies a person or a document.
- Raw tenant data
- Held in memory for the length of the scan and discarded. Never written to disk or a database.
- File contents, email, Teams messages
- Never read. Two permissions would technically allow file contents to be read; the scan reads properties only.
What the report will not claim
A reader is entitled to the difference between “checked and clean” and “not checked”. The report states both on its face.
Not assessed is a result
If a signal could not be read — a permission not granted, an endpoint Microsoft only exposes to a signed-in administrator — the check says so, is left out of the score, and the report states what would unlock it. It is never counted as a pass.
A sample of content, a full inventory of sites
Every site is inventoried. File-level checks run on the largest sites, and the report states how many that was and what share of your content by volume they hold.
Every finding says how it knows
Observed: read directly. Calculated: arithmetic over what was read. Inferred: a proxy — device counts against licence counts, for instance — where the evidence suggests it and Vitals cannot prove it. Each label is printed on the finding.
The partner portal
A portal holding your customers’ findings is secured by your own Microsoft directory rather than by a password we issue.
Microsoft sign-in only
Partners sign in with their own Microsoft work accounts. Your multi-factor and Conditional Access policies apply, and disabling someone in your directory removes their access here. Vitals holds no password for anyone at your company.
You manage who has access
An owner adds and removes people by name. Access is pinned to your own Microsoft tenant, so an address on your team list only works from inside your directory.
Three roles
Owner manages the team. Member sees everything, including opportunity estimates. Viewer sees the portfolio and the reports, and none of the commercial view.
Partner terms: the agreement is accepted online, takes effect on acceptance and runs until either party gives 30 days’ notice. Nothing is scanned in any customer tenant until a Global Administrator of that tenant approves read-only access. The end customer is not a party to the partner’s Terms of Supply.
Common questions
- Who approves access?
- A Global Administrator of the tenant, through Microsoft's own consent screen. Vitals never signs in to your tenant and nobody at Innova Group holds credentials for it.
- Can the assessment change anything?
- No. Every permission requested is a read permission. There is no write permission in the list, so the application cannot alter a setting, a file or a policy.
- How do I remove it?
- Open the Microsoft Entra admin centre, go to Enterprise applications, find Innova Group and delete it. No notice is needed and the delivery email reminds you to do it.
- Where is data processed?
- In the United Kingdom. The Data Processing Agreement sets out the sub-processors, the retention periods and the security measures.
- Who is the data controller?
- You are. Innova Technologies Group Ltd, trading as Innova Group, is the processor under the Data Processing Agreement, which forms part of the Terms of Supply.
Data Processing Agreement →Terms of Supply →Privacy Notice →
What the assessment does with this access: all 27 Microsoft 365 checks, how the assessment works, a full sample report, or pricing.