AssetSort

SEC · Security & Privacy

What the Microsoft 365 permissions actually grant

Plain-language breakdown of the connection.

5 min read

The sync reads your tenant's subscribed licences, directory users, Intune and Entra devices, Entra groups, app-registration credentials, and MFA-registration and risk signals. It writes nothing back. It cannot send mail as anyone and cannot access mailbox content, files or messages. There is one deliberate exception to "read-only": the remote Intune device actions (sync, restart, shut down, Defender quick scan, collect diagnostics, remote lock, retire) that an admin or a scoped MSP technician can trigger from a device's page. Those are real commands and need higher-privilege Intune permissions granted on the app registration and separately consented to by your tenant — until that happens they're simply unavailable, and the read-only sync works exactly the same either way. Credentials for the connection live in Google Secret Manager, never in the application database. Every permission requested is listed for your Global Administrator on Microsoft's own consent screen before anything connects, so you're approving Microsoft's description of the access, not AssetSort's.