Required permissions for Azure Files monitoring with Netwrix Auditor.
Microsoft Graph API Permissions
Permission | Purpose |
---|
User.Read | Basic user information |
User.Read.All | Read all users' profiles |
Assign Graph API Permissions
- Navigate to Azure Active Directory > App registrations
- Select your Netwrix Auditor application
- Go to API permissions > Add a permission
- Select Microsoft Graph > Application permissions
- Select required permissions:
User.Read
and User.Read.All
- Click Grant admin consent for [Your Organization]
Storage Account Permissions
Role | Scope | Purpose |
---|
Reader | Resource Group | List storage accounts |
Storage File Data Privileged Reader | Storage Account | Read file share data |
Storage Blob Data Reader | Storage Account | Access audit logs |
Assign Storage Permissions
- Resource Group: Navigate to Resource Group > Access control (IAM) > Add role assignment > Assign Reader role to your application
- Storage Account: Navigate to Storage Account > Access control (IAM) > Add role assignment > Assign required roles:
- Storage File Data Privileged Reader
- Storage Blob Data Reader