NetworkAccessPolicy.Read.All
Allows the app to read your organization's security and routing network access policies on behalf of the signed-in user.
Merill's Note
For an app to access data in Microsoft Graph, the user or administrator must grant it the permissions it needs. This article lists all the Microsoft Graph APIs and your tenant data that can be accessed by the application (vendor/developer) if you consent to the
NetworkAccessPolicy.Read.Allpermission.If you need to create an audit report of the permissions granted to all the apps in your tenant, you can run the
Export-MsIdAppConsentGrantReportcommand. See How To: Run a quick OAuth app audit of your tenant
| Category | Application | Delegated | 
|---|---|---|
| Identifier | 8a3d36bf-cb46-4bcc-bec9-8d92829dab84 | ba22922b-752c-446f-89d7-a2d92398fceb | 
| DisplayText | Read all security and routing policies for network access | Read security and routing policies for network access | 
| Description | Allows the app to read your organization's network access policies, without a signed-in user. | Allows the app to read your organization's security and routing network access policies on behalf of the signed-in user. | 
| AdminConsentRequired | Yes | No | 
Graph Methods
 → API supports delegated access (access on behalf of a user)
 → API supports app-only access (access without a user)
| Methods | 
|---|
Resources
Granting this permission allows the calling application to access (and/or update) the following information in your tenant.
- cloudApplicationReport
- conditionalAccessSettings
- crossTenantAccess
- crossTenantSummary
- destination
- destinationSummary
- device
- deviceUsageSummary
- entitiesSummary
- filteringPolicy
- filteringPolicyLink
- filteringRule
- forwardingPolicyLink
- forwardingProfile
- fqdnFilteringRule
- remoteNetwork
- tenantStatus
- tlsInspectionPolicyLink
- transactionSummary
- networkaccess-user
- webCategoriesSummary
- webCategoryFilteringRule
Graph reference: cloudApplicationReport
| Property | Type | Description | 
|---|---|---|
| category | microsoft.graph.networkaccess.cloudApplicationCategory | The category of the SaaS application. The possible values are: hostingServices,itServices,accountingAndFinance,businessManagement,productivity,eCommerce,education,marketing,humanResourceManagement,health,security,generativeAi,newsAndEntertainment,operationsManagement,contentManagement,developmentTools,collaboration,crm,communications,dataAnalytics,advertising,supplyChainAndLogistics,projectManagement,transportationAndTravel,cloudComputingPlatform,businessIntelligence,cloudStorage,propertyManagement,contentSharing,customerSupport,sales,productDesign,socialNetwork,onlineMeetings,webmail,internetOfThings,forums,webAnalytics,websiteMonitoring,vendorManagementSystem,personalInstantMessaging,codeHosting,unknownFutureValue. | 
| cloudApplicationCatalogId | String | The ID of the application in the SaaS application catalog. | 
| complianceScore | Int32 | The compliance score of the application. | 
| deviceCount | Int32 | Number of devices under this application. | 
| firstAccessDateTime | DateTimeOffset | Timestamp of the first access to the application. | 
| generalScore | Int32 | The general score of the application. | 
| lastAccessDateTime | DateTimeOffset | Timestamp of the last access to the application. | 
| legalScore | Int32 | The legal score of the application. | 
| name | String | The name of the application (e.g., ChatGPT, Salesforce, Bing). | 
| riskScore | Int32 | The risk score of the application. | 
| securityScore | Int32 | The security score of the application. | 
| totalBytesReceived | Int64 | Total bytes received from the application. | 
| totalBytesSent | Int64 | Total bytes sent to the application. | 
| trafficType | microsoft.graph.networkaccess.trafficType | The type of traffic. The possible values are: internet,private,microsoft365,all,unknownFutureValue. | 
| transactionCount | Int32 | Number of transactions under this application. | 
| userCount | Int32 | Number of users under this application. |