When you grant access to the Microsoft Copilot app instance, Netskope seeks consent for the following permissions from the Microsoft Copilot account:
| Permissions required by Netskope | Description | Purpose | Trade-off if permission is not provided |
|---|---|---|---|
| Permissions required for Successful Instance Creation | |||
| Directory.Read.All | Read directory data | Allows to collect Netskope app service Principal ID. And Also provides access to Application/Agentic App. | Required for successful instance grant; cannot onboard instance into Netskope |
| Domain.Read.All | Read domains | List and read Office 365 domains. | Required for successful instance grant; cannot onboard instance into Netskope |
| LicenseAssignment.Read.All | Read all license assignments. | Allows an app to read license assignments to validate Copilot License | Required for successful instance grant; cannot onboard instance into Netskope |
| Sites.Read.All | Read items in all site collections | Retrieve SharePoint token to access the SharePoint API. | Required for successful instance grant; cannot onboard instance into Netskope |
| Permissions Required for Graph Endpoint Resources | |||
| ExternalConnection.Read.All | Read the properties and relationships of an externalConnection object. | Allows the app to read External connection(Copilot connector) list. | Certain rules related to Copilot connectors will not be available. |
| InformationProtectionPolicy.Read.All | Read all published labels and label policies for an organization. | Allows the app to read Label Policy settings, sensitivity Label. | Certain rules related to LabelPolicySetting and SensitivityLabels will not be available. |
| SensitivityLabel.Read | Reads sensitivityLabel object and its properties using the data security and governance API. | Allows the app to read data security and governance related to sensitivityLabel. | Certain rules related to LabelPolicySetting and SensitivityLabels will not be available. |
| Permissions Required for Exchange Resources | |||
| RoleManagement.Read.Directory | Read all directory RBAC settings | List global admin members. | Certain rules related to Label Policy will not be available. |
| Exchange.ManageAsApp | Manage Exchange As Application | Access Exchange data without user interaction | Certain rules related to Label Policy will not be available. |
| Permissions Required for Sharepoint Resources | |||
| Sites.FullControl.All | Need full control access to read data from SharePoint tenant configuration | Tenant API endpoints reside in the tenant admin site collection, which only tenant admin users or app principals with the `Sites.FullControl.All` permission can access. Although this permission grants full control, SSPM uses it solely for read actions on SharePoint. | Certain rules related to the SharePointTenant asset will always fail and will not be available. Customers can choose to mute these rules if desired. |

