Skip to main content

Graph API Permissions Required for Netwrix Directory Manager V11 Application in Entra ID

Applies to

Netwrix Directory Manager 11

Question

What is the list of Microsoft Graph API application permissions required for the Netwrix Directory Manager in Entra ID? What is the mapping of each permission to the specific Netwrix Directory Manager functionality it enables?

Answer

Here is the list of all the Microsoft Graph API application permissions required for the Netwrix Directory Manager in Entra ID:

Microsoft Teams / Channels

Graph API PermissionNetwrix Directory Manager Feature
Channel.CreateAdd Channel under Team Properties on DM Portal
Channel.Delete.AllRemove any channel under Team Properties on the DM Portal
Channel.ReadBasic.AllRetrieve Channel's Name, Description, and Privacy under Team Properties across the tenant on DM Portal
ChannelMember.Read.AllRetrieve the list of members in any Channel under Team Properties across the tenant on the DM Portal
ChannelMember.ReadWrite.AllRetrieve, Add, Update, and Remove members in/from any Channel under Team Properties across the tenant on DM Portal

Directory and Group Management

Graph API PermissionNetwrix Directory Manager Feature
Directory.Read.AllRetrieve users, groups, roles, and directory settings across the tenant on DM Portal
Directory.ReadWrite.AllRetrieve and manage/modify users, groups, roles, and directory settings across the tenant on DM Portal
Group.CreateCreate any type of group on DM Portal
Group.Read.AllRetrieve the properties and memberships of all groups across the tenant on DM Portal
Group.ReadWrite.AllRetrieve, create, update, and delete groups, manage group members and owners across the tenant on DM Portal
GroupMember.Read.AllRetrieve the group members and owners of all groups across the tenant on DM Portal
GroupMember.ReadWrite.AllRetrieve, add, update, and remove members and owners in/from any group on DM Portal

Microsoft 365 Mail Access

Graph API PermissionNetwrix Directory Manager Feature
Mail.ReadRead the signed-in user's mail including subject, body, and attachments from Microsoft 365 (Outlook) mailboxes
Mail.ReadBasicRead the signed-in user's mail including subject, from, to, cc, and received date from Microsoft 365 (Outlook) mailboxes
Mail.ReadBasic.AllRead all users' mail across the tenant including subject, from, to, cc, and received date from Microsoft 365 (Outlook) mailboxes
Mail.ReadWriteRead and modify (edit, move, delete) emails in your mailbox from Microsoft 365 (Outlook) mailboxes
Mail.SendSend emails as the signed-in user or on behalf of any user from Microsoft 365 (Outlook) mailboxes

User Management

Graph API PermissionNetwrix Directory Manager Feature
User.Read.AllRetrieve all users' profile data across the tenant under User Profiles on DM Portal
User.ReadBasic.AllRetrieve all basic attributes of user profiles across the tenant under User Profiles on DM Portal
User.ReadWrite.AllRetrieve, create, update, and delete users across the tenant on DM Portal
User.Invite.AllInvite users from another Microsoft Entra ID tenant to the membership of any group in your domain
User.DeleteRestore.AllDelete users from DM Portal and access deleted items endpoints
User.EnableDisableAccount.AllEnable/disable accounts of all users from User Properties on DM Portal
User.RevokeSessions.AllForce sign-out users after password reset or role change on DM Portal
User.ManageIdentities.AllRetrieve, update, and delete identities that are associated with a user's account under Linked Mode of DM Portal
User.Export.AllExport user profile data from DM Portal
User-PasswordProfile.ReadWrite.AllManage user's password profiles, change and reset password of all users on DM Portal
User-Phone.ReadWrite.AllRetrieve and update mobile phone of all users under User Properties on DM Portal

Role Management

Graph API PermissionNetwrix Directory Manager Feature
RoleManagement.Read.AllRetrieve assigned roles of all users under Directory Role tab of User Properties across the tenant on DM Portal
RoleManagement.Read.CloudPCRetrieve assigned roles of all users under Directory Role tab of User Properties across the tenant on DM Portal specific to Cloud PC (Windows 365)
RoleManagement.Read.DirectoryRetrieve Microsoft Entra directory roles e.g. Global Administrator under Directory Role tab of User Properties across the tenant on DM Portal
RoleManagement.Read.ExchangeRetrieve assigned roles of all users across Exchange Online
RoleManagement.ReadWrite.CloudPCRetrieve, add, and remove assignments of roles of all users under Directory Role tab of User Properties across the tenant on DM Portal specific to Cloud PC (Windows 365)
RoleManagement.ReadWrite.DirectoryRetrieve, add, and remove assignments of roles of all users under Directory Role tab of User Properties across the tenant on DM Portal
RoleManagement.ReadWrite.ExchangeRetrieve, add, and remove assignments of roles of all users across Exchange Online

Exchange Online (Application Permissions)

Exchange PermissionNetwrix Directory Manager Feature
Exchange.ManageAsAppRetrieve, create, modify mailboxes, manage mailbox permissions on DM Portal or through PowerShell

SharePoint Delegated Permissions

SharePoint PermissionNetwrix Directory Manager Feature
AllSites.FullControlAccess to all SharePoint Sites across the tenant, manage site settings and permissions from Entitlement Portal and Entitlement Section of Microsoft Entra ID Identity Store on Admin Portal
AllSites.ManageCreate/delete sites, manage site users and groups on Entitlement Portal
AllSites.ReadRetrieve the content of all SharePoint sites across the tenant under Entitlement Section of Microsoft Entra ID Identity Store on Admin Portal
AllSites.WriteAdd, edit, and delete documents, list items, and pages of all sites across the tenant