Skip to main content
Read-only · No tenant writes

Exactly what KAIRAVO reads, and what it never touches.

KAIRAVO connects to Microsoft Graph and Defender with read-only permissions. Here is every scope it requests, in plain English.

Read-only scopes only

Every permission KAIRAVO requests ends in .Read.All. No write, remediation, or privileged-operation scope is ever requested.

No writes to your tenant

KAIRAVO never creates, edits, or deletes policies, devices, or assignments. It reads, scores, and reports. Nothing else.

Least privilege by design

Each connector asks only for the narrowest scope that covers its data. Missing a scope degrades one connector, never the whole picture.

Microsoft Graph

Application permissions requested

Granted once, via admin consent. Every scope is read-only.

DeviceManagementManagedDevices.Read.AllRead

Managed device inventory and detected apps

/deviceManagement/managedDevices/deviceManagement/detectedApps
DeviceManagementApps.Read.AllRead

Mobile app catalog and app assignments

/deviceAppManagement/mobileApps
DeviceManagementConfiguration.Read.AllRead

Configuration and compliance policies

/deviceManagement/configurationPolicies
DeviceManagementScripts.Read.AllRead

Device management and remediation scripts (metadata only)

/deviceManagement/deviceManagementScripts
GroupMember.Read.AllRead

Group membership, to map policy assignments

/groups/{id}/members
WindowsUpdates.Read.AllRead

Windows Autopatch update posture

/admin/windows/updates

Microsoft Defender for Endpoint

Optional enrichment permissions

Defender API permissions, separate from Microsoft Graph. Skip them and KAIRAVO scores deterministically without exposure enrichment.

SecurityRecommendation.Read.AllRead

Defender vulnerability management recommendations

Software.Read.AllRead

Software inventory for exposure enrichment (optional)

The line we never cross

What KAIRAVO never requests.

No write scope, no remediation action, no directory changes. If a permission can alter your tenant, KAIRAVO does not ask for it.

DeviceManagementManagedDevices.ReadWrite.All
DeviceManagementConfiguration.ReadWrite.All
DeviceManagementApps.ReadWrite.All
DeviceManagementScripts.ReadWrite.All
Any device wipe, retire, or sync action
Directory write or password-reset scopes

Your data and AI

Deterministic first. AI only if you opt in.

Deterministic by default

Every finding can be produced by the rules engine from evidence templates, with no AI in the loop. That is the default mode for a pilot.

EU-hosted AI is optional

Explanations can be enriched by Azure OpenAI in an EU data zone, enabled only after a data-handling review and DPA. It is off until you approve it.

Your data stays scoped

KAIRAVO reads posture and configuration metadata, not user files or mail. The AI option sees finding evidence summaries, never raw credentials.

For data residency, subprocessors, and retention, see the privacy policy.

Want the permissions list for your security review?

We will send the exact consent URL and scope list before anything connects. Built by UgurLabs.