Microsoft Entra ID Governance

Configure configuration management service permissions

In brief

Learn how to assign or remove the application permissions and roles that the Tenant Configuration Management service uses to create snapshots and run monitors

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

Open on Microsoft Learn ↗

The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.

Set up permissions for tenant monitoring

This article describes how to manage the permissions that theConfigure configuration management service needspermissions

Use the Configuration management permissions page to access resources identified in a monitor. An administrator must assign or remove permissions for the Tenant Configuration Management service. The service uses these permissions manually. Two types ofto create snapshots and run monitors.

Configure service permissions before you create snapshots or monitors that include the corresponding workload resources. Missing service permissions can cause a snapshot to be managed inincomplete or a monitor run to fail.

When you create a monitor or snapshot, thePermissions step shows whether the service has the least-privilege permissions for the resource types you selected. This step is read-only. If the wizard shows that required least-privilege permissions are missing, use the Configuration management permissions page to add them.

Prerequisites

  • A Microsoft Entra admin center: applicationrole that can assign or remove app-only permissions and Microsoft Entra roles.

    The permission type you assign depends on the services you need to monitor:

    • Microsoft Entra ID and Intune: Assign application permissions. This approach is the least-privileged way to enable monitoring. For example, to monitor conditional access policies, the configuration managementfor service needs the Policy.Read.All application permission. Ifprincipals in your policies reference other resource types, you might also need permissions like User.Read.All or RoleManagement.Read.All.
    • Teams: Assign the Teams Reader role. Teams doesn't have granular application permissions, so assigning the configuration management service to the Teams Reader role is the least-privileged way to enable monitoring.
    • Exchange, Security, and Compliance (Purview and Defender): Assign permissions locally within the admin experiences for those services. Built-in Microsoft Entra roles grant more permissions than needed for these monitoring scenarios.

    Prerequisites

    Browse to configurationOpen Configuration management permissions

    To open the permissions page, follow these steps:

    1. Sign in to the Microsoft Entra admin center.
    2. Browse to Tenant Governance > Configuration management permissions.

    Manage applicationAssign permissions

    To manage applicationAssign permissions based on the workloads that the configuration management service uses to access resources:

    • Select the Application permissions tab at the top of the page.

    Add application permissions

    1. Select Add permissions in the command bar.
    2. Search for and select the application permissions that the configuration management service needs to accesscontain the resources you want to monitor.
    3. Select Save at the bottom of the context pane.

    Remove application permissions

    1. Select the checkbox next to the permission name, then select the Delete button in the command bar. Alternatively, hover over the permission and select the delete icon that appears.
    2. In the confirmation dialog, select Remove.

    Manage Microsoft Entra roles

    To manage Microsoft Entra roles assigned to the configuration management service:snapshot or monitor:

    Add a Microsoft Entra role

    1. Select Add Entra role in the command bar.

      Remove permissions

      To remove a permission or a Microsoft Entra role, select the checkbox next to its name, and then select Remove in the command bar.

      Related content

    Remove a Microsoft Entra role

    1. Select the checkbox next to the role name, then select the Delete button in the command bar. Alternatively, hover over the role and select the delete icon that appears.Exchange Online RBAC for applications
    2. In the confirmation dialog, select Remove.

    Related content