Security & Trust

Entra Analyzer is built for security-conscious organizations. Here is how we protect your data and respect your tenant.

Read-only access

We only request read-only Microsoft Graph permissions. Entra Analyzer will never modify settings, create users, roles, or policies, or write any data back to your tenant.

EU data residency

All data is stored and processed in the European Union. Our infrastructure runs on Azure in the EU West region.

No agents to install

Entra Analyzer connects via the Microsoft Graph API. There is nothing to deploy on-premises and no software to install on your devices.

Data deletion on disconnect

If you revoke consent or cancel your subscription, all stored scan data for your tenant is permanently deleted.

Encryption in transit and at rest

All connections use TLS 1.2+. Data at rest is encrypted using Azure-managed keys in our EU-hosted database.

Contact for security questions

support@entraanalyzer.com

Required permissions

All permissions below are read-only Microsoft Graph application permissions. Nothing is ever written back to your tenant.

PermissionPurpose
Directory.Read.AllRead directory data (users, groups, roles)
User.Read.AllRead all user profiles and properties
AuditLog.Read.AllRead sign-in activity and audit logs
Group.Read.AllRead all groups and memberships
Application.Read.AllRead all application registrations
RoleManagement.Read.DirectoryRead directory role assignments
Policy.Read.AllRead Conditional Access and security policies
UserAuthenticationMethod.Read.AllRead users' authentication methods (MFA)
Device.Read.AllRead device objects and compliance state
DeviceManagementManagedDevices.Read.AllRead Intune managed devices
IdentityRiskEvent.Read.AllRead Identity Protection risk events
AccessReview.Read.AllRead access reviews configuration
EntitlementManagement.Read.AllRead entitlement management configuration