A security tool has to be trustworthy first. Cloud Audit Check is read-only, least-privilege, encrypted, and hosted in Australia — so connecting your tenant is a low-risk decision.
Your data is hosted in Australia (Sydney). It does not leave the country — a hard requirement for many Australian businesses and government-adjacent work.
Cloud Audit Check requests read-only Microsoft Graph permissions. It reads your configuration to assess it; it never changes a setting in your tenant.
We ask only for the specific Graph permissions each check needs — nothing broad, nothing write-capable. You see the full list before you consent.
Connection is via Microsoft admin consent. Remove the app from Entra, or disconnect in-app, and access ends immediately.
Secrets (like your Azure app credential) are encrypted with AES-256-GCM before they ever touch the database. They are never returned to the browser.
We store assessment results and findings so you can track progress — not your emails, files, or user content. The audit reads configuration, not data.
Exactly what we ask for
No write access, no mailbox or file content. You approve these in Microsoft’s own admin-consent screen.
Policy.Read.AllRead Conditional Access, authentication methods, and security-default policies.Organization.Read.AllRead tenant and licence information.Directory.Read.AllRead users, groups, roles, and domains for identity checks.RoleManagement.Read.DirectoryRead privileged role assignments (e.g. Global Administrators).Application.Read.AllRead enterprise apps and service principals for integration checks.SecurityEvents.Read.AllRead Microsoft Secure Score and control profiles.AuditLog.Read.AllRead per-user MFA registration and sign-in telemetry.MailboxSettings.ReadDetect inbox rules that forward mail externally — reads rules only, never message content.SharePointTenantSettings.Read.AllRead the tenant-wide SharePoint / OneDrive external-sharing setting.DeviceManagementManagedDevices.Read.AllRead Intune device compliance state.DeviceManagementConfiguration.Read.AllRead Intune compliance and configuration policies.Azure is optional and uses role-based access, not Graph permissions: assign the same app registration the read-only Reader and Security Reader roles on your subscription.
Connect your tenant for a free audit — and disconnect the moment you want to.