Documentation

Permission model

How TenantVigil uses Microsoft 365 permissions and why manual remediation remains the safer default.

Read-only assessmentsGuided remediationFramework mappingReporting & drift monitoring

Need a hands-on starting point?

Run a free assessment or talk to the team if you want help evaluating fit, permissions, or rollout approach.

Assessment permissions

TenantVigil uses Microsoft Graph application permissions and supporting Microsoft 365 administrative verification paths to read tenant configuration and security posture. The assessment model is designed to avoid write access during normal posture evaluation.

This keeps the default onboarding posture aligned with least privilege while still allowing TenantVigil to gather evidence across Entra ID, Exchange Online, Teams, SharePoint, Intune, and Purview-related control families.

Manual remediation versus automation

Manual remediation is the recommended path because it allows the customer or MSP to apply changes directly inside Microsoft 365 or PowerShell while TenantVigil remains read-only.

If automation is ever requested for a control, TenantVigil treats that as a separate decision. Write-capable remediation would require additional consent, review, and a clear understanding that broader settings access is being delegated to the platform.

What customers should expect

Customers should expect read-oriented access for assessments and an explicit warning whenever a workflow would require additional write permissions.

  • Default assessments are read-oriented
  • The Free plan is limited to one full assessment per month
  • TenantVigil Business enables recurring monitoring and individual control refreshes
  • Automation review is separate from standard assessment consent