| Directory.Read.All | Enumerate users, groups, admin roles, license assignments — the input to ~40 CMMC L2 controls. |
| Policy.Read.All | Read Conditional Access, authentication strength, identity-protection policies. |
| Policy.ReadWrite.ConditionalAccess | Apply the auto-remediation queue — only when the MSP approves a fix. |
| AuditLog.Read.All | Mirror the unified audit log into Stella's append-only evidence store. |
| SecurityEvents.Read.All | Pull Microsoft 365 Defender alerts for SI / IR control coverage. |
| DeviceManagementConfiguration.Read.All | Read Intune device baselines for CM / MA / MP control coverage. |
| DeviceManagementConfiguration.ReadWrite.All | Push approved Intune policy fixes when the MSP triggers auto-remediation. |
| Reports.Read.All | Pull Secure Score breakdown, sign-in reports, license usage. |
| Mail.Read | Sample inbox forwarding rules + transport rule audits (read-only, never message bodies). |