Exactly what KAIRAVO reads, and what it never touches.
KAIRAVO connects to Microsoft Graph and Defender with read-only permissions. Here is every scope it requests, in plain English.
Read-only scopes only
Every permission KAIRAVO requests ends in .Read.All. No write, remediation, or privileged-operation scope is ever requested.
No writes to your tenant
KAIRAVO never creates, edits, or deletes policies, devices, or assignments. It reads, scores, and reports. Nothing else.
Least privilege by design
Each connector asks only for the narrowest scope that covers its data. Missing a scope degrades one connector, never the whole picture.
Microsoft Graph
Application permissions requested
Granted once, via admin consent. Every scope is read-only.
DeviceManagementManagedDevices.Read.AllReadManaged device inventory and detected apps
DeviceManagementApps.Read.AllReadMobile app catalog and app assignments
DeviceManagementConfiguration.Read.AllReadConfiguration and compliance policies
DeviceManagementScripts.Read.AllReadDevice management and remediation scripts (metadata only)
GroupMember.Read.AllReadGroup membership, to map policy assignments
WindowsUpdates.Read.AllReadWindows Autopatch update posture
Microsoft Defender for Endpoint
Optional enrichment permissions
Defender API permissions, separate from Microsoft Graph. Skip them and KAIRAVO scores deterministically without exposure enrichment.
SecurityRecommendation.Read.AllReadDefender vulnerability management recommendations
Software.Read.AllReadSoftware inventory for exposure enrichment (optional)
The line we never cross
What KAIRAVO never requests.
No write scope, no remediation action, no directory changes. If a permission can alter your tenant, KAIRAVO does not ask for it.
DeviceManagementManagedDevices.ReadWrite.AllDeviceManagementConfiguration.ReadWrite.AllDeviceManagementApps.ReadWrite.AllDeviceManagementScripts.ReadWrite.AllAny device wipe, retire, or sync actionDirectory write or password-reset scopesYour data and AI
Deterministic first. AI only if you opt in.
Deterministic by default
Every finding can be produced by the rules engine from evidence templates, with no AI in the loop. That is the default mode for a pilot.
EU-hosted AI is optional
Explanations can be enriched by Azure OpenAI in an EU data zone, enabled only after a data-handling review and DPA. It is off until you approve it.
Your data stays scoped
KAIRAVO reads posture and configuration metadata, not user files or mail. The AI option sees finding evidence summaries, never raw credentials.
For data residency, subprocessors, and retention, see the privacy policy.
Want the permissions list for your security review?
We will send the exact consent URL and scope list before anything connects. Built by UgurLabs.