Inget lösenord delas. Vi läser din konfiguration med din egen åtkomst, aldrig ett mejl eller en fil. Du stänger av åtkomsten när du vill.
Information om språk. Dokument: Det du godkänner - SYAGA Audit. Avsnitt som visas på engelska: 2 av 76. Den franska versionen av detta dokument är referensversionen. Skriv till contact@syaga.eu för att få en version på ditt språk.
No write is possible: our application holds no write permission, Microsoft would refuse it. The scan runs in your browser; our server only ever sees tokens, never your data in clear text. Your results live in memory: they leave when you tick the discharge box, once you have downloaded your files, and no later than 2 hours after the end of the scan (24 hours for what you send us yourself). Only your billing data remains, which the law requires us to keep for 10 years.
Your journey opens 5 successive Microsoft consent screens (checking your audit log, then the scan, then the Exchange, Teams and Power Platform deep dives). This page details the scan one. Microsoft will list 45 permissions there, one by one. It is long, and that is normal: Microsoft splits its read permissions very finely. Here is the same list, grouped by domain. Compare it line by line: if a permission shows up on the Microsoft screen without appearing here, do not consent. All 45 are read-only (Read): none of them allows writing, changing or deleting anything.
User.Read : Reads your own profile, to know who is running the audit. Nothing else.Directory.Read.All : Reads the directory (accounts, groups, registered applications, domains). This is the bedrock of the diagnostic: who exists, who is an administrator.AdministrativeUnit.Read.All : Reads administrative units, that is how your directory is carved up by site, department or subsidiary.Policy.Read.All : Reads your conditional access, password and authentication method policies.Policy.Read.PermissionGrant : Reads the rule that decides whether a user can, alone, authorise a third-party application.ConsentRequest.Read.All : Reads application requests awaiting your approval.AuthenticationContext.Read.All : Reads your authentication contexts, the assurance tiers attached to sensitive actions.Agreement.Read.All : Reads the terms of use you present to your users at sign-in.AuditLog.Read.All : Reads the audit log and sign-in history. This is what reveals intrusion attempts, and it is also what lets you check afterwards everything we read.Reports.Read.All : Reads usage reports (MFA actually in use, dormant licences).ReportSettings.Read.All : Reads a single setting: whether your reports are anonymised.RoleManagement.Read.Directory : Reads directory role assignments, so who is an administrator today.RoleManagement.Read.All : Reads PIM-eligible roles, so who can become an administrator on demand.RoleManagementAlert.Read.Directory : Reads PIM alerts (too many standing administrators, privileged accounts without MFA).PrivilegedAccess.Read.AzureADGroup : Reads privilege elevation obtained through group membership. A classic blind spot.DelegatedAdminRelationship.Read.All : Reads delegated administration relationships, so which providers hold privileged access to your tenant.AccessReview.Read.All : Reads your access reviews, the campaigns that periodically recheck entitlements.EntitlementManagement.Read.All : Reads your access packages and their approvers.LifecycleWorkflows-Workflow.ReadBasic.All : Reads the joiner and leaver automation for your staff.IdentityRiskEvent.Read.All : Reads Microsoft risk detections (sign-in from an anonymous address, credentials found in a leak).IdentityRiskyUser.Read.All : Reads the list of accounts Microsoft flags as risky.IdentityRiskyServicePrincipal.Read.All : The same thing for application identities, not people.SecurityEvents.Read.All : Reads your Microsoft secure score and the detail of its controls.SecurityAlert.Read.All : Reads security alerts.SecurityIncident.Read.All : Reads incidents, that is the alerts Microsoft has grouped together.AttackSimulation.Read.All : Reads your phishing simulation campaigns, if you run any.DeviceManagementManagedDevices.Read.All : Reads the inventory of managed devices (encryption, compliance, OS version).DeviceManagementConfiguration.Read.All : Reads the configuration and compliance profiles being applied.DeviceManagementServiceConfig.Read.All : Reads general Intune settings (enrolment, Autopilot).DeviceManagementApps.Read.All : Reads the applications you distribute and their protection policies.DeviceManagementScripts.Read.All : Reads the scripts pushed to your endpoints. Rarely reviewed, often carrying secrets.DeviceManagementRBAC.Read.All : Reads who holds which rights inside Intune.DeviceLocalCredential.ReadBasic.All metadata only : This is about LAPS, the backup of the local administrator password. We call /directory/deviceLocalCredentials without asking for the credentials field: we see that a backup exists and how old it is, never the password.What Microsoft writes: To access the actual passwords on the device, done by including $select=credentials as part of the query parameters, the app must be assigned the DeviceLocalCredential.Read.All permission and DeviceLocalCredential.ReadBasic.All is insufficient. Microsoft sourceSharePointTenantSettings.Read.All : Reads tenant sharing settings (external sharing, anonymous links, expiry).Sites.Read.All : Used to inventory your sites (/sites/getAllSites). Let us be precise, because this is the broadest one on the list: as Microsoft defines it, it would also allow reading documents. Our code only does the inventory, and your audit log shows it request by request. That is exactly why we ask for AuditLog.Read.All: so that you can check it yourself, without taking our word for it.TeamworkAppSettings.Read.All : Reads tenant-wide Teams app settings.AppCatalog.Read.All : Reads the catalogue of Teams applications allowed in your tenant.RecordsManagement.Read.All : Reads your retention labels and policies.SubjectRightsRequest.Read.All : Reads your data subject rights requests under the GDPR (access, erasure): that they exist and how they are tracked, not their content.BackupRestore-Configuration.Read.All : Reads your Microsoft 365 backup policies, if any exist.BitlockerKey.ReadBasic.All metadata only : Tells whether a BitLocker recovery key exists for a device and when it was backed up. We call /informationProtection/bitlocker/recoveryKeys without $select=key: the key itself is never returned to us.What Microsoft writes: By default, this operation doesn't return the key property that represents the actual recovery key. To include the key property in the response, use the $select OData query parameter. Including the $select query parameter triggers a Microsoft Entra audit of the operation and generates an audit log. Microsoft sourceNetworkAccess.Read.All : Reads your network access configuration (Global Secure Access), if you use it.ServiceHealth.Read.All : Reads the health state of your Microsoft services.ServiceMessage.Read.All : Reads message center posts, the changes Microsoft announces to you.OrgSettings-Forms.Read.All : This is about Microsoft Forms: the organisation-level settings of the service (who may create forms, external sharing, collecting responses from outside the organisation). We read those settings, never the content of a form or any response.RoleManagement.Read.Directory is a subset of RoleManagement.Read.All: we keep both because Microsoft documents one for part of the role reads and the other for PIM-eligible roles.Mail.*), no chat permission (Chat.*), and no write permission (ReadWrite). And no offline_access: we keep no access after the diagnostic. Your token lives about one hour, in memory, then it is gone.oauth2PermissionGrants), not copied from our own declarations. If the two ever diverged, it would show.Innan du startar diagnosen, berätta vem du är. Beroende på din storlek och din bransch gäller inte samma skyldigheter för dig (GDPR, NIS2, DORA): det är det som gör dina slutsatser rättvisande. Vi kategoriserar, vi bestämmer aldrig åt dig. Offentliga data från INSEE, ingen känslig information här.
Källa: Recherche d'Entreprises, INSEE Sirene, officiella offentliga data.
Förhandsåtkomst: i detta skede kan endast en inbjuden Microsoft 365-klientorganisation köra en verklig diagnos. Är din ännu inte inbjuden stoppas processen före all insamling och du hamnar på väntelistan.
Sales are not open in this language yet. The terms you would have to accept here are not fully written in your language, and we will not ask you to accept a text you cannot read. Sales are open in the languages below. You can also write to contact@syaga.eu.
Information om språk. Dokument: Personuppgiftsbiträdesavtal (DPA). Avsnitt som visas på engelska: 4 av 161. Den franska versionen av detta dokument är referensversionen. Skriv till contact@syaga.eu för att få en version på ditt språk.
The report is a diagnostic: it states what is observed, it does not fix anything on your behalf.
Så bevisar vi det