Table of Contents

ConfigurationMonitoring.Read.All

Allows the app to read all Configuration Monitoring entities on behalf of the signed-in user.

Merill's Note

For an app to access data in Microsoft Graph, the user or administrator must grant it the permissions it needs. This article lists all the Microsoft Graph APIs and your tenant data that can be accessed by the application (vendor/developer) if you consent to the ConfigurationMonitoring.Read.All permission.

If you need to create an audit report of the permissions granted to all the apps in your tenant, you can run the Export-MsIdAppConsentGrantReport command. See How To: Run a quick OAuth app audit of your tenant

Category Application Delegated
Identifier aca929ec-9830-44dc-bda1-85cf938aaa95 c645bb69-adc4-4242-b620-02e635f03bf6
DisplayText Read all Configuration Monitoring entities Read all Configuration Monitoring entities
Description Allows the app to read all Configuration Monitoring entities, without a signed-in user. Allows the app to read all Configuration Monitoring entities on behalf of the signed-in user.
AdminConsentRequired Yes Yes

Graph Methods

Resources

Granting this permission allows the calling application to access (and/or update) the following information in your tenant.

Graph reference: configurationBaseline

Property Type Description
description String User-friendly description of the baseline given by the user.
displayName String User-friendly name given by the user to the baseline.
id String The unique identifier for the configurationBaseline object. Inherited from entity.
parameters baselineParameter collection Collection of parameters attached to the baseline.
resources baselineResource collection Collection of resources and their properties that are added to the baseline. At least one property of one resource must be present in the baseline.