Files
vigil365/docs/graph-permissions.md
Samir KhanandClaude Sonnet 4.6 54ad152f31 Initial commit: M365 Security Alert Dashboard
Full-stack Microsoft 365 security monitoring dashboard built with
ASP.NET Core 8 + React 18 + TypeScript. Aggregates security signals
from Microsoft Graph API across Defender XDR, Entra ID Protection,
Intune, Exchange Online, and M365 Compliance into a single
self-hosted dashboard.

Features:
- 13 monitoring pages: Identity, Devices, Email, Incidents, Compliance,
  Service Health, Licenses, Conditional Access, Audit Log, Sign-in Locations,
  M365 Connectivity, Alert Center, Overview
- Alert Policy Engine with 9 pre-built templates and custom policy builder
- Detail modals with direct M365 portal deep links per item type
- Per-page search, filter, sort, CSV export, saved filter presets
- Dark/light mode, collapsible sidebar, toast notifications
- Responsive layout, sticky filter bars, sortable table columns

All credentials must be supplied via .NET User Secrets (dev) or
appsettings.Production.json (prod) — never committed to source.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-16 21:41:48 +05:30

16 lines
681 B
Markdown

# Graph Permission Reference
Use application permissions for unattended local collection.
| Feature | Permission |
| --- | --- |
| Risky users | `IdentityRiskyUser.Read.All` |
| Risky sign-ins and failed sign-ins | `AuditLog.Read.All` |
| MFA registration reports | `Reports.Read.All` |
| Intune managed devices | `DeviceManagementManagedDevices.Read.All` |
| Defender XDR incidents | `SecurityIncident.Read.All` |
| Defender XDR alerts | `SecurityAlert.Read.All` |
| Microsoft 365 service health | `ServiceHealth.Read.All` |
Admin consent is required. Some tenants also require an Entra directory role or product-specific role assignment for the application/service principal.