Connect Microsoft 365 to Black Cat SSPM
Connect your Microsoft 365 tenant so Black Cat can review users, admin roles, conditional access, authentication methods, applications, domains and Copilot agents.
≈ 15 min · audit access · write-capable permissions are flagged below
What Black Cat reads, and why
| Permission | What it lets Black Cat do | Status |
|---|---|---|
User.Read.All | Lets Black Cat list users and their security settings. | Required |
Directory.Read.All | Lets Black Cat review directory roles, group membership and guest accounts. | Required |
Domain.Read.All | Lets Black Cat check that your domains are verified and that SPF, DKIM and DMARC records exist. | Required |
Application.Read.All | Lets Black Cat review registered applications, their credentials and the permissions they hold. | Required |
Policy.Read.All | Lets Black Cat review tenant policies such as consent rules, password protection and authentication methods. | Required |
ConditionalAccessPolicy.Read.All | Lets Black Cat review conditional access policies and what they require of your users. | Required |
Organization.Read.All | Lets Black Cat see tenant-wide settings and the licences assigned to your organization. | Required |
Group.Read.All | Lets Black Cat review groups, their membership and guest access to group content. | Required |
ExchangeManage.ReadWrite.All | Lets Black Cat review Exchange Online protection settings such as Customer Lockbox and mailbox auditing. The write side of this permission is not used. | Required Write (write-capable permission) |
Power Platform API — https://api.powerplatform.com/.default (application permission) | Lets Black Cat inventory the Copilot Studio agents published in your tenant. | Required |
AI Administrator or AI Reader (Microsoft Entra directory role) | Lets Black Cat see every published Copilot Studio agent, not only the ones an ordinary reader can view. | Required |
AuditLog.Read.All | Lets Black Cat read sign-in events for location and anomaly checks (requires an Entra ID P1 licence). | Optional |
Reports.Read.All | Lets Black Cat see usage and multi-factor registration reports for your users. | Optional |
What you'll need
- Directory (tenant) identifier Required — Shown on the overview page of your Microsoft Entra directory.
- Application (client) identifier Required — Shown on the read-only app registration you create for Black Cat.
- Client secret Required — Created on the same app registration under Certificates & secrets.
Where to create it
- Setup guide (Microsoft 365) ↗ (opens in new tab)
- Developer documentation (Microsoft 365) ↗ (opens in new tab)
What we check on Microsoft 365 →