Microsoft Graph

Microsoft Graph for MSP security posture assessment

SecurityScore.me uses read-only Microsoft Graph access to assess Microsoft 365 posture across customer tenants. Delegated permissions, multi-tenant consent, and least-privilege scopes designed for MSP operations.

Why the assessment runs on Graph

Microsoft Graph is the API behind the Microsoft 365 admin surfaces. Reading posture through it is what makes a portfolio-wide assessment possible without a login per tenant.

Programmatic instead of portal-by-portal

The admin centers are built for a single tenant administrator clicking through screens. Graph exposes the same posture data programmatically, so one assessment can cover Secure Score, Conditional Access, Defender, and identity across many customer tenants.

That is the difference between a review you can run weekly across fifty clients and one you run once a year on the clients that asked.

Read-only by design

SecurityScore.me requests delegated read-only permissions. It reads posture data and produces findings. It has no permission to change Conditional Access, roles, sharing, or any other tenant configuration.

Remediation stays with your team, in your normal change process, using Microsoft’s own tools.

Consent is per customer

Each customer tenant is connected through its own consent flow, scoped to that customer workspace. Connecting or disconnecting one customer does not touch any other.

What is read from Graph

Secure Score

Score, history, and recommended actions per connected tenant.

Conditional Access

Policy configuration, conditions, and exclusions for identity posture.

Defender for Endpoint

Device posture and alerts where the customer is licensed.

Identity signals

Users, groups, authentication methods, privileged roles, and risky sign-ins.

Sharing and admin config

External sharing settings and administrative role assignments.

Licences and service state

Licence assignment and service context that frame the rest of the posture data.

Security and auditability

Least-privilege scopes

The connection requests only the Graph permissions the assessment needs. The exact scopes are shown during tenant connection so you and the customer can review them before consenting.

Token handling and access

Access is exercised only when assessments and scheduled re-checks run. MSP team access to a connected customer is governed by organization roles, and every connection, scan, and settings change is written to the activity log.

Revocable at any time

Consent for a customer tenant can be withdrawn from the Microsoft side or by removing the workspace. Once revoked, no further posture data is read for that customer.

Priority customers

Related pages

Frequently asked questions

Next steps

See Microsoft Graph integration in a demo