Permissions Aegis Eight requests
Aegis Eight is a read-only, multi-tenant Microsoft Entra application. When a Global Administrator grants consent, it can read the security configuration needed to assess your Essentials posture — and nothing else.
The short version
- Read-only. We cannot create, modify, or delete anything in your tenant.
- No access to your content. We cannot read your emails, OneDrive or SharePoint files, or Teams messages.
- Your data never trains AI.We never use customer data to train any machine-learning model — ours or anyone else’s.
- Stored in Australia. Customer scan data is stored in Australia by default; dedicated deployments in another region are available on request.
- Verifiable evidence. API-derived findings are stamped with the endpoint, timestamp, and SHA-256 hash of the data we used to score them. Auditors can independently re-query and verify.
- Revoke anytime. Removing consent immediately stops all access.
What we access
- Security and policy configuration (e.g. Conditional Access, MFA policies)
- Which MFA and authentication methods are registered
- Device compliance and operating-system version state
- Admin roles and privileged-access configuration
- Microsoft 365 Backup protection and restore evidence
What we never access
- Your email or mailbox content
- Your files in OneDrive or SharePoint
- Your Teams messages
- Passwords or MFA settings — we cannot change anything
- Any tenant other than the one that granted consent
How you grant access
A Global Administrator approves read-only access through Microsoft Entra’s one-click admin consent flow when you start a trial or subscription:
- Enter your work email and choose Microsoft 365 on the trial form.
- Sign in as a Global Administrator (or delegated admin with consent rights).
- Review the read-only Graph scopes and approve admin consent.
- Aegis Eight scans your tenant and emails the maturity report PDF.
For the wider operational picture — data flows, retention, tenant isolation, sub-processors — see the Security & Privacy page. Google Workspace uses domain-wide delegation instead — see Google permissions.
Why we need these permissions
Each permission maps to a specific ASD Essentials control. Aegis Eight requests the minimum set of read scopes required to score your maturity automatically — instead of relying on a questionnaire. The detailed breakdown below names every scope, what it reads, and which control it supports.
We preserve evidence, not just a score
Most Essentials tools are questionnaire engines with a few API checks bolted on. Aegis Eight is different: every Graph response that informs a finding is captured, sha256-hashed, and the hash is stamped into the finding itself.
The result is a cryptographically verifiable evidence chain — an auditor, cyber insurer, or regulator can confirm that the data we scored is exactly what your tenant returned, without taking our word for it. See how it works in the evidence-chain section of the whitepaper.
Detailed permission breakdown
Every permission below is read-only.
Opt-in modules for broader Essentials coverage
These permissions are grouped into optional capability modules, each backed by its own read-only Microsoft Entra application registration. The core scan above uses a single core app; each module below is a separate app you consent to only if you enable it (per ADR-0010). Modules you do not enable are never granted at the Microsoft layer. Enabling a module later triggers its own admin-consent screen — never bundled with the core app.
Identity Risk
Adds Entra ID Identity Protection signals (risky users, risk detections) to detect compromised or at-risk accounts that undermine MFA effectiveness.
Security Operations
Surfaces open Microsoft 365 Defender incidents, Secure Score cross-checks, and Defender TVM patch-age evidence.
Governance
Adds tenant governance signals such as role-assignable group hygiene for ISO 27001 / NIST / CIS alignment.
Data-handling promises
- No machine-learning training.We never use customer Microsoft Graph data to train any ML model — ours, a vendor’s, or a third-party’s. No exceptions, including embeddings and retrieval indexes.
- Australian data residency. Customer scan data is stored in Australia by default; dedicated deployments in another region are available on request.
- Plan-tiered retention. Full evidence (raw API response bodies) is retained for 90 days on Business, 12 months on Growth, and per contract on Enterprise. Free / trial assessments follow the shorter trial window. See pricing and Security & Privacy.
- Hash-bound evidence chain. We preserve a verifiable evidence chain: every Graph response that informs a finding is captured, SHA-256 hashed, and linked to the finding. An assessor can re-query Microsoft Graph (within retention windows) and confirm the data matches exactly what we scored — without taking our word for it. Details in the Security & Privacy whitepaper.
- No cross-tenant correlation.Findings derived from one customer’s tenant are never combined with another customer’s data in the same query, report, or dashboard.
- Revocation purges within 30 days. A Global Administrator can remove Aegis Eight from your tenant at any time and additionally request full data deletion.
Full details, sub-processor list, and certification posture in the Security & Privacy whitepaper.
Revoking consent
A Global Administrator can remove Aegis Eight’s access at any time via Microsoft Entra admin centre → Enterprise applications → Aegis Eight → Properties → Delete. Revocation is immediate from Microsoft’s side: any subsequent API call from Aegis Eight fails authorization and no new tenant data can be collected. Aegis Eight detects the loss of access on the next scan attempt and stops. You can additionally request deletion of any data already collected (purged within 30 days — see the Security & Privacy whitepaper).
Questions about a specific permission? Email [email protected]. Compare with Google Workspace permissions or read the full operational detail in the Security & Privacy whitepaper.