Insights for Power Platform

    When you create the Insights forPower Platform app profile in AvePoint Online Services, the AvePoint Insights forPower Platform app will be automatically set up in your Microsoft Entra ID.

    The table below lists the permissions that should be accepted when you authorize the AvePoint Insights for Power Platform app.

    APIPermissionTypePurpose
    Microsoft GraphGroup.Read.All(Read all groups)ApplicationRetrieve information about groups in your organization.
    Microsoft GraphUser.Read.All(Read all users’ full profiles)ApplicationRetrieve information of Power BI users.
    Microsoft GraphAuditLog.Read.All(Read all audit log data)ApplicationRetrieve the last sign-in time of external users.
    Microsoft GraphDirectory.Read.All(Read directory data)ApplicationRetrieve data from your organization’s directory.
    Office 365 Management APIsActivityFeed.Read (Read activity data for your organization)ApplicationRetrieve activity data in your organization.
    Microsoft Information Protection Sync ServiceUnifiedPolicy.Tenant.Read (Read all unified policies of the tenant)ApplicationRetrieve sensitivity label information configured in the tenant from Microsoft 365.
    Power BI ServiceTenant.Read.All(View all content in tenant)DelegatedRetrieve information of Power BI workspaces.
    Power BI ServiceDataset.Read.All(View all datasets)DelegatedRetrieve datasets in Power BI workspaces.

    *Note: Consent from a Microsoft 365 Global Administrator or a Privileged Role Administrator is required when creating the Insights forPower Platform app profile and must be retained. However, the consent can be revoked if you only use the delegated permissions to manage Power BI workspaces and artifacts via Insights. The authentication user must have a Power BI Pro, Premium Per User (PPU), or Power BI (free) license, and have at least the Fabric Administrator role (the former Power BI admin role).