Skip to content

Connect Microsoft 365 to Black Cat SSPM

Version française

Connect your Microsoft 365 tenant so Black Cat can review users, admin roles, conditional access, authentication methods, applications, domains and Copilot agents.

≈ 15 min · audit access · write-capable permissions are flagged below

What Black Cat reads, and why

PermissionWhat it lets Black Cat doStatus
User.Read.AllLets Black Cat list users and their security settings.Required
Directory.Read.AllLets Black Cat review directory roles, group membership and guest accounts.Required
Domain.Read.AllLets Black Cat check that your domains are verified and that SPF, DKIM and DMARC records exist.Required
Application.Read.AllLets Black Cat review registered applications, their credentials and the permissions they hold.Required
Policy.Read.AllLets Black Cat review tenant policies such as consent rules, password protection and authentication methods.Required
ConditionalAccessPolicy.Read.AllLets Black Cat review conditional access policies and what they require of your users.Required
Organization.Read.AllLets Black Cat see tenant-wide settings and the licences assigned to your organization.Required
Group.Read.AllLets Black Cat review groups, their membership and guest access to group content.Required
ExchangeManage.ReadWrite.AllLets Black Cat review Exchange Online protection settings such as Customer Lockbox and mailbox auditing. The write side of this permission is not used.Required Write (write-capable permission)
Power Platform API — https://api.powerplatform.com/.default (application permission)Lets Black Cat inventory the Copilot Studio agents published in your tenant.Required
AI Administrator or AI Reader (Microsoft Entra directory role)Lets Black Cat see every published Copilot Studio agent, not only the ones an ordinary reader can view.Required
AuditLog.Read.AllLets Black Cat read sign-in events for location and anomaly checks (requires an Entra ID P1 licence).Optional
Reports.Read.AllLets Black Cat see usage and multi-factor registration reports for your users.Optional

What you'll need

  • Directory (tenant) identifier Required — Shown on the overview page of your Microsoft Entra directory.
  • Application (client) identifier Required — Shown on the read-only app registration you create for Black Cat.
  • Client secret Required — Created on the same app registration under Certificates & secrets.

Where to create it

What we check on Microsoft 365 →

Other setup guides

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications are based on publicly available documentation and may change over time.

See your own SaaS posture in 10 minutes

Run a free posture scan — no credit card required, read-only-by-default access you can revoke any time.

Run a free posture scan