Microsoft 365 Permissions

The tables below detail the Microsoft 365 management permissions that can be assigned to permission groups in EnPower.

Microsoft 365 Tenant Level Permissions

Exchange

Accessible reportAvailable actionDescription
ContactsCreate mail contactsCreate mail contacts.
ContactsManage mail contactsManage mail contacts, including the basics, contact information, and organization.
ContactsDelete mail contactsDelete mail contacts
ContactsExport reportsExport mail contacts into reports.
End of Life reportExport End of Life reportExport End of Life report of mailboxes.

Teams

Accessible reportAvailable actionDescription
Call quality report-Access the call quality report.
End of Life reportExport End of Life reportExport End of Life report of Teams.

Groups

Accessible reportAvailable actionDescription
GroupsCreate on-premises groupsCreate on-premises groups in the tenants that the selected containers belong to.
End of Life reportDelete Groups permanentlyDelete Groups permanently on the Delete Groups report page.
End of Life reportRestore deleted GroupsRestore the deleted Groups on the Delete Groups report page.
End of Life reportExport End of Life reportExport End of Life report of Groups.

Users

Accessible reportAvailable actionDescription
Deleted users reportDelete users permanentlyDelete users permanently on the Delete users report page.
Deleted users reportRestore deleted usersRestore the deleted users on the Delete users report page.

SharePoint

Accessible reportAvailable actionDescription
Deleted sites reportDelete sites permanentlyDelete sites permanently on the Delete sites report page.
Deleted sites reportRestore deleted sitesRestore the deleted sites on the Delete sites report page.
End of Life reportExport End of Life reportExport End of Life report of sites.

Loop

Accessible reportAvailable actionDescription
End of Life reportExport End of Life reportExport End of Life report of Loop sites.

Exchange dashboards

Accessible reportDescription
Mailbox summary chartsView and manage gadgets for the mailbox summary charts on Dashboard, including the Mailbox activity chart, Storage chart, and the Storage quota chart.
Mailbox activity chartsView and manage gadgets for the mailbox activity charts on Dashboard, including the Mailbox action chart and the Meeting action chart.

Teams dashboards

Accessible reportDescription
Teams activity chartView and manage gadgets for the Teams user activity chart on Dashboard.
Device chartView and manage gadgets for the Device usage chart on Dashboard.
PSTN and SMS chartsView and manage gadgets for the Calling plans/SMS chart and the Direct routing chart on Dashboard.

Groups dashboards

Accessible reportDescription
Groups activity charts-

User dashboards

Accessible reportDescription
User activity chartsView and manage gadgets for the user activity charts on Dashboard, including the Active users chart, the User activity chart, and the Microsoft 365 Services chart.
Microsoft 365 Apps activity chartsView and manage gadgets for the Microsoft 365 Apps activity charts, including the App users chart and the Platform users chart.
User activation chartsView and manage gadgets for the User activation charts on Dashboard, including the Desktop activation chart, the Mobile app activation chart, and the User activation chart.

SharePoint dashboards

Accessible reportDescription
File activityView and manage gadgets for the selected report charts on Dashboard.
Page activityView and manage gadgets for the selected report charts on Dashboard.
User activityView and manage gadgets for the selected report charts on Dashboard.
Active sitesView and manage gadgets for the selected report charts on Dashboard.
Active filesView and manage gadgets for the selected report charts on Dashboard.
StorageView and manage gadgets for the selected report charts on Dashboard.
Page viewsView and manage gadgets for the selected report charts on Dashboard.

OneDrive dashboards

Accessible reportDescription
File activityView and manage gadgets for the selected report charts on Dashboard.
User activityView and manage gadgets for the selected report charts on Dashboard.
Active accountsView and manage gadgets for the selected report charts on Dashboard.
Active filesView and manage gadgets for the selected report charts on Dashboard.
StorageView and manage gadgets for the selected report charts on Dashboard.

Compliance dashboards

Accessible reportDescription
Administration compliance > Global admin warningView and manage gadgets for the global admin warning chart on Dashboard.
Top 10 compliance risks > Top 10 external domainsView and manage gadgets for the Top 10 external domains chart on Dashboard.

Metadata & bulk creation

Accessible reportAvailable actionDescription
Bulk creation templateCreateCreate bulk creation templates.
Bulk creation templateEditEdit bulk creation templates.
Bulk creation templateDeleteDelete bulk creation templates.

Microsoft 365 Container Level Permissions

Exchange

Accessible reportAvailable actionDescription
MailboxesCreate mailboxesCreate user mailboxes.
*Note: This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.
MailboxesDelete mailboxesDelete user mailboxes.
MailboxesSearch for mailbox forwardingSearch for mailboxes that are automatically forwarding emails to specific internal recipients
MailboxesManage mailboxesManage user mailboxes, including to edit information for basics, update settings, and archive user mailboxes.
MailboxesManual syncManually retrieve the latest data of selected objects.
MailboxesLitigation holdManage the litigation hold settings of mailboxes.
MailboxesManage mailbox delegationManage user mailbox delegation settings, including the contacts folder delegation, calendar delegation, and mailbox delegation settings.
MailboxesCopy permissionCopy permission of a mailbox to another one.
MailboxesCheck if mailbox existsCheck if the mailbox still exists.
MailboxesExport reportsExport user mailboxes into reports.
MailboxesTrigger workflowsTrigger the manually triggered workflows to manage or report the selected user mailboxes.
MailboxesCreate on-premises shared mailboxCreate on-premises shared mailboxes.
MailboxesManage organization units for on-premises mailboxesMove hybrid mailboxes from one organization unit to another.
MailboxesTrigger contact election taskTrigger contact election task for mailboxes.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
MailboxesApply renewal profileApply renewal profile created in Cloud Governance to shared mailboxes.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
MailboxesApply contact election profileApply contact election profile created in Cloud Governance to shared mailboxes.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
MailboxesRestart renewalRestart the renewal process of shared mailboxes.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
MailboxesAuto-complete renewalComplete the renewal process of shared mailboxes.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
MailboxesAssign renewal tasksUpdate the assignees of a shared mailbox’s renewal.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
MailboxesSpecify contactsSpecify contacts for shared mailboxes.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
MailboxesEdit metadataEdit the Cloud Governance metadata applied to the shared mailboxes.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
MailboxesRemove from Cloud Governance.Remove registered mailboxes from Cloud Governance.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
ResourcesCreate resource mailboxesCreate resource mailboxes.*Note: This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.
ResourcesDelete resource mailboxesDelete resource mailboxes
ResourcesManage resource mailboxesManage resource mailboxes, including to edit information for the basics, resource address, and configure booking options.
ResourcesManual syncManually retrieve the latest data for the selected resource mailboxes.
ResourcesManage resource mailbox delegationManage resource mailboxes delegation, including both resource and calendar delegation.
ResourcesExport reportsExport resource mailboxes into reports.
ResourcesSpecify contactsSpecify contacts for resource mailboxes.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
ResourcesEdit metadataEdit the Cloud Governance metadata applied to the resource mailboxes.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
ResourcesRemove from Cloud Governance.Remove registered resource mailboxes from Cloud Governance.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
Mailbox activityExport reportsView and export mailbox activity reports.
Mail usersManage mail usersIncluding mail users and guest mail users.
*Note: guest mail users can only be managed in Users module.
Mail usersDelete mail usersIncluding mail users and guest mail users.
*Note: guest mail users can only be deleted in the Users module.
Mail usersExport reportsExport mail users into reports.

Teams

Accessible reportAvailable actionDescription
TeamsCreate TeamsCreate Teams.
Note the following:
This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.
If selected, you can also configure whether only users in this group's manageable tenants or user containers can be added to Groups during Group creation
TeamsDelete TeamsDelete Teams.
TeamsManage TeamsManage Teams, including basics, channels, and settings.
TeamsManage membershipsManage memberships, including Team memberships, channel memberships, and policies.
TeamsManual syncManually retrieve the selected Teams’ latest data.
TeamsDownload permission reportDownload Teams’ permission report.
*Note: This is only available when you have a subscription for AvePoint Insights.
TeamsExport reportsExport Teams into reports.
TeamsTrigger workflowsTrigger the manually triggered workflows to manage or report the selected Teams.
TeamsAppy renewal profileApply renewal profile created in Cloud Governance to Teams.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
TeamsRestart renewalRestart the renewal process of Teams.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
TeamsAuto-complete renewalComplete the renewal process of Teams.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
TeamsRemove from Cloud Governance.Remove registered Teams from Cloud Governance.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
TeamsEdit metadataRemove Teams’ Cloud Governance metadata.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
TeamsSpecify contactsSpecify primary and secondary contacts for Teams.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
TeamsAssign renewal tasksUpdate the assignee of Teams’ renewal task.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
TeamsApply contact election profileApply contact election profile to Teams.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
Teams auditsExport reportsView and export Teams audit reports.
Teams activity reportExport reportsView and export Teams activity reports.
Channel reportCreate channelsCreate new channels.
Channel reportDelete channelsDelete channels from Teams.
Channel reportManage channelsUpdate channel information.
Channel reportManage membershipView and update channel membership.
Channel reportExport reportExport channel report into Excel files.
Device reportExport reportsView and export Teams device reports.
User reportEdit policiesAccess Teams user report and edit user policies.
PSTN and SMS report-Access PSTN and SMS report.
Sensitivity reportApply sensitivity labelsApply sensitivity labels to Teams’ objects.
Sensitivity reportRemove permissionsRemove user permissions for Teams’ objects.

Groups

Accessible reportAvailable actionDescription
GroupsCreate GroupsCreate Groups, including Microsoft 365 Groups, distribution groups, security groups, and mail-enabled security groups.
Note the following:
This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.
If selected, you can also configure whether only users in this group's manageable tenants or user containers can be added to Groups during Group creation
GroupsManage GroupsManage Group properties.
GroupsManage membershipsManage Group memberships.
GroupsDelete GroupsDelete Groups.
GroupsExport reportsExport Groups into reports.
GroupsTrigger workflowsTrigger the manually triggered workflows to manage or report the selected Groups.
GroupsManage organizational units for on-premises groupsManage organizational units for on-premises groups.
GroupsManual syncManually retrieve the selected Groups’ latest data.
GroupsApply renewal profileApply renewal profile created in Cloud Governance to groups.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
GroupsApply contact election profileApply contact election profile created in Cloud Governance to groups.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
GroupsRestart renewalRestart the renewal process of groups.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
GroupsAuto-complete renewalComplete the renewal process of groups.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
GroupsAssign renewal tasksUpdate the assignees of a group renewal.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
GroupsSpecify contactsSpecify contacts for groups.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
GroupsEdit metadataEdit the Cloud Governance metadata applied to the groups.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
GroupsRemove from Cloud GovernanceRemove registered Groups from Cloud Governance.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
Groups activity reportExport reportsView and export Group activity reports.

Users

Accessible reportAvailable actionDescription
UsersCreate usersCreate Microsoft 365 users.
*Note: This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.
UsersCreate users/Invite users > Assign licenses and appsAssign licenses and apps when creating or inviting users.
UsersCreate users/Invite users > Create users in all containers/Invite users to all containersCreate or invite users to containers that is not in the permission group’s manageable scope.
UsersInvite usersInvite external users to your as guests in your organization.
*Note: This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.
UsersCreate on-premises usersCreate on-premises users in your local Active Directory.
UsersManage organizational units for on-premises usersManage the organization units of your on-premises users.
UsersEdit user detailsEdit users’ detailed information.
UsersManage admin rolesManage the administration roles of users.
UsersManage user licensesAssign or remove user licenses.
UsersManage security settingsManage settings, including password settings, user sessions, sign-in settings, and MFA settings.
UsersDelete usersDelete users.
UsersExport reportsExport users into reports.
UsersTrigger workflowsTrigger the manually triggered workflows to manage or report the selected users.
UsersRemove from Cloud GovernanceRemove registered users from Cloud Governance.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
UsersEdit metadataEdit metadata applied to the guest user.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
UsersTrigger contact election taskTrigger contact election task of the guest user.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
UsersSpecify contactsSpecify primary and secondary contacts of the guest user.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
UsersApply renewal profileApply renewal profile to the guest user.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
UsersApply contact election profileApply contact election profile to the guest user.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
UsersRestart renewalRestart the renewal process of the guest user.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
UsersAuto-complete renewalAutomatically complete the renewal process of the guest user.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
UsersAssign renewal tasksAssign the renewal tasks of the guest user to other assignees.
Sign-in reportConfigure MFA settingsConfigure the MFA settings for users in the Sign-in report.
Sign-in reportReset MFA settingsReset the MFA settings for users in the Sign-in report, including restoring the user’s authentication status, resetting the user’s authentication methods, and deleting the app passwords generated by this user.
Sign-in reportRevoke sessionsRevoke all sessions for the user and require the user to re-sign in on all devices in the Sign-in report.
Sign-in reportReset passwordManually or automatically reset the password for users in the Sign-in report.
Sign-in reportBlock sign-inBlock users from signing in.
Sign-in reportExport reportsView and export sign-in reports.
User activity reportExport reportsView and export user activity reports.
Microsoft 365 Apps activity reportExport reportsExport Microsoft 365 Apps activity report.
User activation reportExport reportsExport user activation reports.

SharePoint

Accessible reportAvailable actionDescription
SharePoint sitesCreate sitesCreate SharePoint online sites.
Note the following:
This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.
If selected, you can also configure whether only users in this group's manageable tenants or user containers can be added to Groups during Group creation
SharePoint sitesManage sites > BasicsEdit site basic information.
SharePoint sitesManage sites > HubManage sites’ hub settings.
SharePoint sitesManage sites > Connect to new Microsoft 365 GroupConnect sites to Microsoft 365 Group.
SharePoint sitesManual syncManually retrieve the selected sites’ latest data.
SharePoint sitesArchive/ReactivateArchive sites or reactive archived sites.
SharePoint sitesManage permissionsManage site permissions, including site admins, site owners, site members, and site visitors.
SharePoint sitesManage settingsManage site settings, including the sharing, sensitivity, storage settings, and site status.
SharePoint sitesDelete sitesDelete sites.
SharePoint sitesExport reportsExport SharePoint Online sites into reports.
SharePoint sitesTrigger workflowsTrigger the manually triggered workflows to manage or report the selected sites.
SharePoint sitesApply renewal profileApply renewal profile created in Cloud Governance to SharePoint sites.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
SharePoint sitesApply contact election profileApply contact election profile created in Cloud Governance to SharePoint sites.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
SharePoint sitesRestart renewalRestart the renewal process of SharePoint sites.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
SharePoint sitesAuto-complete renewalComplete the renewal process of SharePoint sites.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
SharePoint sitesAssign renewal tasksUpdate the assignees of SharePoint sites’ renewal.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
SharePoint sitesSpecify contactsSpecify contacts for SharePoint sites.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
SharePoint sitesEdit metadataEdit Cloud Governance metadata of the sites.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
SharePoint sitesRemove from Cloud GovernanceRemove registered SharePoint sites from Cloud Governance.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
Group team sitesCreate sitesCreate SharePoint Online Group team sites.
*Note: This is a tenant-level permission. If selected, group members can create objects in the tenants that the selected containers belong to.
Group team sitesManage sites > BasicsEdit sites’ basic information.
Group team sitesManage sites > HubUpdate sites’ hub settings.
Group team sitesManual syncManually retrieve the selected sites’ latest data.
Group team sitesArchive/ReactivateArchive sites or reactive archived sites.
Group team sitesManage permissionsManage Group team site permissions, including primary admin, additional admins, site owners, site members, and site visitors.
Group team sitesManage settingsManage Group team site settings, including the sharing, sensitivity, storage settings, and site status.
Group team sitesDelete sitesDelete Group team sites.
Group team sitesExport reportsExport Group team sites into reports.
Group team sitesTrigger workflowsTrigger the manually triggered workflows to manage or report the selected sites.

OneDrive

Accessible reportAvailable actionDescription
OneDriveManage administratorsManage OneDrive administrators.
OneDriveManage external sharingManage external sharing settings for OneDrive.
OneDriveManage storage limitManage storage limit for OneDrive.
OneDriveManual syncManually retrieve the latest data of the selected OneDrive.
OneDriveAssign licenseAssign license to OneDrive accounts.
OneDriveExport reportsExport OneDrive into reports.
OneDriveUpdate OneDrive statusLock or unlock the OneDrive.
OneDriveTrigger workflowsTrigger the manually triggered workflows to manage or report the selected OneDrive.
OneDriveApply renewal profileApply renewal profile created in Cloud Governance to OneDrive.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
OneDriveRestart renewalRestart the renewal process of OneDrive.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
OneDriveEnable/Disable assessmentEnable or disable OneDrive assessment in AvePoint Insights and Cloud Governance.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
OneDriveAuto-complete renewalComplete the renewal process of OneDrive.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.

Loop

Accessible reportAvailable actionDescription
LoopManage settingsManage basic workspace settings including sensitivity label assignment.
LoopManage permissionsManage workspace permissions.
LoopDeleteDelete workspaces.
LoopExport reportsExport workspace properties into reports.
LoopManual syncManually retrieve the latest Loop site data.
LoopApply renewal profileApply renewal profile created in Cloud Governance to Loop sites.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
LoopRestart renewalRestart the renewal process of Loop sites.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
LoopAuto-complete renewalAuto complete the renewal process of Loop sites.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
LoopAssign renewal tasksAssign renewal tasks Loop sites to new assignees.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
LoopSpecify contactsSpecify primary and secondary contacts for Loop sites.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
LoopEdit metadataEdit metadata applied to Loop sites.
*Note: This is only available when you have a subscription for AvePoint Cloud Governance.
LoopRemove from Cloud GovernanceRemove Loop sites from Cloud Governance.
Note: This is only available when you have a subscription for AvePoint Cloud Governance.

Teams dashboards

Accessible reportDescription
Teams user adoptionAccess the default Teams user adoption dashboard, and manage gadgets for the Active users, 1:1 calls and meetings, Audio and video time (min), Chats, Active users in departments, Chats in departments, Audio and video time in departments (min), 1:1 calls and meetings in departments charts.
Teams activityAccess the default Teams activity dashboard, and manage gadgets for the Teams without owners, Inactive Teams, Top 10 Teams by members, Top 10 Teams by channels, Top 10 Teams by activity, Public vs Private Teams, Empty Teams, Teams with external users charts.
Teams usersAccess the default Teams users dashboard, and manage gadgets for the Active users, Inactive users, Active vs Inactive users charts.

SharePoint dashboards

Accessible reportDescription
Total storage usedView and manage the selected report charts on the default SharePoint activity and usage dashboard or custom SharePoint tenant-level dashboards.
Total filesView and manage the selected report charts on the default SharePoint activity and usage dashboard or custom SharePoint tenant-level dashboards.
Top 10 inactive sitesView and manage the selected report charts on the default SharePoint activity and usage dashboard or custom SharePoint tenant-level dashboards.
Top 10 sites by storageView and manage the selected report charts on the default SharePoint activity and usage dashboard or custom SharePoint tenant-level dashboards.
Top 10 sites by activityView and manage the selected report charts on the default SharePoint activity and usage dashboard or custom SharePoint tenant-level dashboards.

OneDrive dashboards

Accessible reportDescription
Total storage usedView and manage the selected report charts on the OneDrive activity and usage dashboard or custom OneDrive tenant-level dashboards.
Total filesView and manage the selected report charts on the OneDrive activity and usage dashboard or custom OneDrive tenant-level dashboards.
Storage used by blocked usersView and manage the selected report charts on the OneDrive activity and usage dashboard or custom OneDrive tenant-level dashboards.
Files of blocked usersView and manage the selected report charts on the OneDrive activity and usage dashboard or custom OneDrive tenant-level dashboards.
Top 10 users by storageView and manage the selected report charts on the OneDrive activity and usage dashboard or custom OneDrive tenant-level dashboards.

Compliance dashboards

Accessible reportDescription
Exchange complianceAccess the default Exchange compliance dashboard, and manage gadgets for the Litigation hold enabled mailboxes, Mailboxes forwarding to external domains, Mailboxes forwarding to specific domains, Litigation hold enabled mailboxes in departments, Mailboxes forwarding to external domains in departments, Mailboxes forwarding to specific domains in departments charts.
Administration complianceAccess the default Administration compliance dashboard, and manage gadgets for the Users with administrative roles, Global administrators, OneDrive with multiple administrators, Administrative role assignments, Users with administrative roles in departments, OneDrive with multiple administrators in departments charts.
User access complianceAccess the default User access compliance dashboard, and manage gadgets for the Users without strong password, Password changed/reset users, Sign-in failed users, Users with multiple IP addresses, Strong password required, Users without strong password in departments, Password never expires, Password never expired users in departments, MFA status, MFA disabled users in departments, Password changed/reset users in departments, Sign-in failed users in departments, Sign-in failed users with multiple IP addresses in departments, Failed sign-ins in departments charts.
Collaboration complianceAccess the default Collaboration compliance dashboard, and manage gadgets for the External links, External users, Sensitive items, External links trend, External users trend, Sensitive items trend charts.
Top 10 compliance risksAccess the default Top 10 compliance risks dashboard, and manage gadgets for the Top 10 countries with failed sign-ins, Top 10 departments with failed sign-ins, Top 10 sign-in failed users, Top 10 OneDrive with multiple administrators charts.

Metadata & bulk creation

Accessible reportAvailable actionDescription
MetadataCreateCreate Cloud Governance metadata in EnPower.
MetadataEditEdit Cloud Governance metadata settings and values in EnPower.
MetadataDeleteDelete Cloud Governance metadata from EnPower.

Microsoft 365 Workflow Permissions

Dynamic workflow triggered by trigger events

Manageable object typeAvailable trigger eventAvailable workflow action
UsersCreate/Invite userAssign licenses
UsersCreate/Invite userAdd to the Group
UsersCreate/Invite userAdd to the Team
UsersCreate/Invite userShare user calendar
UsersCreate/Invite userSend email to manager or specified users
UsersCreate/Invite userPre-provision OneDrive
UsersCreate/Invite userManage mailbox archive
UsersCreate/Invite userManage litigation hold
UsersCreate/Invite userManage email apps settings
UsersCreate/Invite userManage language and time
UsersCreate/Invite userSet working hour time zone
UsersCreate/Invite userConfigure MFA settings
UsersCreate/Invite userAssign roles
UsersCreate/Invite userAssign to administrative units
UsersDelete userSend email to manager or others
UsersDelete userReassign user’s Group ownership to others
UsersDelete userReassign user’s Team ownership to others
UsersDelete userReassign user’s OneDrive administrator permission to others
UsersBlock userAssign others as user’s OneDrive administrator
UsersBlock userReassign user’s Group ownership to others
UsersBlock userReassign user’s Team ownership to others
UsersBlock userRemove licenses
UsersBlock userRemove from the Group
UsersBlock userRemove from the Team
UsersBlock userArchive mailbox
UsersBlock userConvert user mailbox to shared
UsersBlock userConfigure mailbox automatic replies
UsersBlock userConfigure mailbox delegation
UsersBlock userAdd others as user’s mailbox delegate
UsersBlock userSend email to manager or specified users
UsersUpdate userAssign licenses
UsersUpdate userRemove licenses
UsersUpdate userAdd to the Group
UsersUpdate userAdd to the Team
UsersUpdate userRemove from the Group
UsersUpdate userRemove from the Team
UsersUpdate userSend email to manager or specified users
UsersPassword reset/changeBlock user
UsersPassword reset/changeSend email to manager or specified users
UsersFailed sign-in
*Note: A Microsoft Entra ID P1 or P2 license is required to detect this event.
Delete user
UsersFailed sign-in
*Note: A Microsoft Entra ID P1 or P2 license is required to detect this event.
Block user
UsersFailed sign-in
*Note: A Microsoft Entra ID P1 or P2 license is required to detect this event.
Send email to manager or specified users
Microsoft TeamsAdd user to TeamSend email to Team owners
Microsoft TeamsAdd user to TeamSend email to specific users
Microsoft TeamsAdd user to TeamSend email to primary contact
Microsoft TeamsAdd user to TeamSend email to secondary contact
GroupsAdd user to Group
*Note: This trigger event is currently only applicable to Microsoft 365 Groups.
Send email to Group owners
GroupsAdd user to Group
*Note: This trigger event is currently only applicable to Microsoft 365 Groups.
Send email to specific users
GroupsAdd user to Group
*Note: This trigger event is currently only applicable to Microsoft 365 Groups.
Send email to primary contact
GroupsAdd user to Group
*Note: This trigger event is currently only applicable to Microsoft 365 Groups.
Send email to secondary contact
SharePointSharePoint sites file accessRemove access
SharePointSharePoint sites file accessBlock user
SharePointSharePoint sites file accessSend email to manager or specified users
SharePointSharePoint sites file accessApply sensitivity label
SharePointGroup team site file accessRemove access
SharePointGroup team site file accessBlock user
SharePointGroup team site file accessSend email to manager or specified users
SharePointGroup team site file accessApply sensitivity label
SharePointAdd user to SharePoint siteSend email to site owners
SharePointAdd user to SharePoint siteSend email to site admins
SharePointAdd user to SharePoint siteSend email to specific users
SharePointAdd user to SharePoint siteSend email to primary contact
SharePointAdd user to SharePoint siteSend email to secondary contact
SharePointAdd user to Group team siteSend email to Group owners
SharePointAdd user to Group team siteSend email to site admins
SharePointAdd user to Group team siteSend email to site owners
SharePointAdd user to Group team siteSend email to specific users
SharePointAdd user to Group team siteSend email to primary contact
SharePointAdd user to Group team siteSend email to secondary contact
OneDriveFiles accessRemove access
OneDriveFiles accessBlock user
OneDriveFiles accessSend email to specific users
OneDriveFiles accessApply sensitivity label

Dynamic workflow triggered by object conditions

Manageable object typeAvailable workflow action
MailboxesHide from address list
MailboxesSend emails
MailboxesTrigger contact election task
MailboxesSpecify contacts
MailboxesApply renewal profiles
MailboxesApply contact election profile
MailboxesRestart renewal
MailboxesAuto-complete renewal
MailboxesAssign renewal tasks
MailboxesEdit metadata
ResourcesHide from address list
ResourcesSend emails
ResourcesEdit metadata
Microsoft TeamsRemove all guests
Microsoft TeamsArchive/Unarchive Teams
Microsoft TeamsApply sensitivity label
Microsoft TeamsManage Team/channel settings
Microsoft TeamsSend emails
Microsoft TeamsApply renewal profile
Microsoft TeamsRestart renewal
Microsoft TeamsTrigger contact election task
Microsoft TeamsEdit metadata
Microsoft TeamsApply contact election profile
Microsoft TeamsAssign renewal tasks
Microsoft TeamsAuto-complete renewal
Microsoft TeamsSpecify contacts
GroupsTrigger contact election task
GroupsApply renewal profile
GroupsRestart renewal
GroupsApply sensitivity label
GroupsChange privacy setting
GroupsHide from address list
GroupsSend emails
GroupsEdit metadata
GroupsAssign renewal tasks
GroupsAuto-complete renewal
GroupsSpecify contacts
GroupsApply contact election profile
UsersRemove licenses
UsersRemove duplicate licenses
UsersBlock sign-in
UsersTrigger contact election task
UsersSpecify contacts
UsersApply renewal profile
UsersApply contact election profile
UsersRestart renewal
UsersAuto-complete renewal
UsersAssign renewal tasks
UsersRemove from Cloud Governance
UsersEdit metadata
SharePointArchive/Reactivate
SharePointRestart renewal
SharePointTrigger contact election task
SharePointChange site status
SharePointEdit storage limit
SharePointApply sensitivity label
SharePointSend emails
SharePointApply renewal profile
SharePointEdit metadata
SharePointApply contact election profile
SharePointAssign renewal tasks
SharePointAuto-complete renewal
SharePointSpecify contacts
OneDriveManage administrators
OneDriveManage storage limit
OneDriveManage external sharing
OneDriveUpdate OneDrive status
OneDriveAssign license
OneDriveSend emails
OneDriveApply renewal profile
OneDriveRestart renewal
OneDriveEnable/Disable assessment

Manually triggered workflow

Manageable object typeAvailable workflow action
ExchangeConvert user mailbox to shared
ExchangeArchive mailbox
ExchangeHide from address list
ExchangeConfigure mailbox automatic replies
ExchangeAdd others as user’s mailbox delegate
ExchangeConfigure mailbox delegation
ExchangeSend email to mailbox users
ExchangeSend email to manager
ExchangeSend email to mailbox delegates
ExchangeSend email to specific users
ExchangeSend email to primary and secondary contacts
TeamsUpdate Team owners
TeamsUpdate Team members
TeamsRemove all guests
TeamsArchive Teams
TeamsUpdate sensitivity label
TeamsManage Team privacy setting
TeamsManage Team/channel setting
TeamsSend email to Team owners
TeamsSend email to Team members
TeamsSend email to specific users
TeamsSend email to primary and secondary contacts
GroupsUpdate Group owners
GroupsUpdate Group members
GroupsRemove specified users
GroupsSend email to Group owners
GroupsSend email to Group members
GroupsSend email to specific users
GroupsSend email to primary and secondary contacts
UsersConvert mailbox to shared
UsersArchive mailboxes
UsersHide from address list
UsersAdd others as user’s mailbox delegate
UsersConfigure mailbox automatic replies
UsersConfigure mailbox delegation
UsersAssign others as user’s OneDrive administrator
UsersUpdate Group owners
UsersUpdate Group members
UsersAssign licenses
UsersReplace licenses
UsersRemove licenses
UsersBlock users
UsersDelete users
UsersReset password
UsersConfigure MFA settings
UsersSend email to user
UsersSend email to manager
UsersSend email to mailbox delegates
UsersSend email to specific users
SharePointUpdate site owners
SharePointUpdate site visitors
SharePointUpdate site members
SharePointUpdate additional admins
SharePointRemove specific users
SharePointArchive/Reactivate
SharePointUpdate sensitivity label
SharePointEdit storage limit
SharePointManage sharing settings
SharePointUpdate site status to read only
SharePointDelete sites
SharePointSend email to site owners
SharePointSend email to site visitors
SharePointSend email to site members
SharePointSend mail to specified users
OneDriveAssign others as user’s OneDrive administrator
OneDriveManage sharing settings
OneDriveEdit storage limit
OneDriveUpdate OneDrive status to read only