Why Microsoft admin consent is required for Essentials assessments
Why Entra admin consent (and Google domain-wide delegation) is required for ASD Essentials cloud assessments — what read-only access means, what we never see, and how to revoke.
Connecting a third-party app to Microsoft 365 often triggers the same reaction: why does this need a Global Administrator?
For ASD Essentials assessments that read tenant security configuration — MFA policies, Conditional Access, device compliance, admin roles — administrator approval is not optional. Microsoft and Google both require it before any application can query organisation-wide settings.
This guide explains why, what Aegis Eight can and cannot see, and how to revoke access when you are done.
Why Microsoft requires admin consent
Microsoft Graph application permissions that read tenant-wide security configuration are granted only through admin consent. A standard user cannot approve them. That is intentional: those APIs expose organisation posture, not a single mailbox.
Typical Essentials-relevant signals include:
- Conditional Access and MFA enforcement posture
- Which authentication methods users have registered
- Intune device compliance and OS version state
- Directory admin roles and privileged-access configuration
- Backup or retention evidence where APIs expose it
None of that is available through delegated “sign in as me” alone for a full tenant assessment. Microsoft’s admin-consent screen is the control point that lets a Global Administrator (or equivalent) approve — or refuse — the request.
Google Workspace uses the same principle
Google does not use Entra admin consent. Instead, Workspace admins authorise domain-wide delegation in Admin Console for a service account and a declared OAuth scope list.
The trust decision is the same: only an administrator can grant organisation-wide, read-only API access. Aegis Eight never asks for Gmail, Drive, Chat, or calendar content scopes. See Google permissions for the exact list.
What “read-only” means in practice
Every Graph and Admin SDK scope Aegis Eight requests is read-only. There is no write surface in the product.
We cannot:
- Read emails or mailbox content
- Read SharePoint, OneDrive, Drive, or Shared Drive files
- Read Teams, Chat, or Meet messages
- Modify settings, reset passwords, or create users
We can read security and policy configuration metadata needed to score ASD Essentials maturity (ML0–ML3). Full scope lists: Microsoft 365 permissions and Google Workspace permissions. Technical detail: Security & Privacy.
How long does an assessment take?
After consent (or Google delegation) is granted, a free scan usually finishes in 2–5 minutes. The Essentials PDF is emailed when the run completes. Continuous monitoring (subscription) re-scans on a schedule and alerts on material drift — still read-only.
Can I revoke access afterwards?
Yes.
- Microsoft 365: Remove the Aegis Eight enterprise application from Entra admin center (Enterprise applications). Scanning stops when tokens can no longer be issued.
- Google Workspace: Remove or edit the domain-wide delegation entry for our client ID in Admin Console.
You can also request data deletion from the dashboard after cancellation. Retention details are on the Security & Privacy page.
Is this “ACSC compliant”?
No product should claim that. Aegis Eight assesses your Microsoft 365 or Google Workspace tenant against ASD Essentials maturity levels and produces evidence you can show insurers, boards, or assessors. Alignment is about your configuration — not a certification badge from ACSC.
Start a free assessment
If you are ready to see your maturity score:
- Enter a work email on the homepage trial
- Review the permission list before you grant access
- Approve read-only admin consent (or configure Google domain-wide delegation)
- Download the report when it arrives
No agents. No software to install. No card required for the free scan.