Security Review

With AvePoint tyGraph, permissions are similar to those you have already approved in your environment for legacy tyGraph. Depending on when you signed up for legacy tyGraph, some new permissions have been added to support reports such as Copilot Adoption and Sites that I Own. You can let AvePoint create an app in Microsoft Entra ID automatically or bring your own app registration if you need to customize the permission set.

See Automate App Creation in Microsoft Entra ID for more information on how to automatically create apps in Microsoft Entra ID.

NOTE

Some reports may not show data if permissions are removed.

Most organizations will want to conduct a new security review, so we recommend starting that process early to ensure it is completed before you are ready to upgrade.

Permissions Required

Refer to API Permissions required by tyGraph to see the API permissions that should be accepted when you give consent to the corresponding apps.

  • tyGraph Suite

  • tyGraph for Viva Engage

  • tyGraph for SharePoint

  • tyGraph for Copilot Adoption / Trials

  • tyGraph Pages (Only)

Permission Comparison Between Legacy tyGraph and AvePoint tyGraph

The table below lists the differences in permissions between legacy tyGraph and AvePoint tyGraph.

PermissionsClaimPermission typetyGraph for Viva EngagetyGraph for SharePointtyGraph EnterpriseAvePoint tyGraph
Microsoft GraphDirectory.Read.All DelegatedYesYesYesNo 
Microsoft GraphSites.Read.All DelegatedNoYesNoNo 
Microsoft GraphUser.Read DelegatedYesNoYes Yes 
Microsoft GraphGroup.Read.All ApplicationNoNoYes Yes 
Microsoft GraphGroupMember.Read.All ApplicationNoNoNo Yes 
Microsoft GraphSites.Read.All ApplicationNoYesYesYes 
Microsoft GraphCallRecords.Read.All ApplicationNoNoYesYes 
Microsoft GraphDirectory.Read.All ApplicationYesYesYes Yes 
Microsoft GraphUser.Read.All ApplicationYesYesYes Yes 
Microsoft GraphFiles.Read.All ApplicationNoYesYes Yes 
Microsoft GraphChannelMember.Read.All ApplicationNoNoNo Yes 
Microsoft GraphChannelMessage.Read.All ApplicationNoNoYes Yes 
Microsoft GraphReports.Read.All ApplicationYesYesYes Yes 
Microsoft GraphChannel.ReadBasic.All ApplicationNoNoNo Yes 
Microsoft GraphTeam.ReadBasic.All ApplicationNoNoNo Yes 
Microsoft GraphTeamsTab.Read.All ApplicationNoNoNo Yes 
Office 365ActivityFeed.Read ApplicationYesYesYesYes
Management APIsActivityFeed.Read ApplicationYesYesYesYes
Office 365Sites.Read.All ApplicationNoNoYesYes
SharePoint OnlineSites.Read.All ApplicationNoNoYesYes
Office 365AllSites.FullControl DelegatedNoYesNoNo
SharePoint OnlineAllSites.FullControl DelegatedNoYesNoNo
Office 365Sites.FullControl.All ApplicationNoYesNoYes
SharePoint OnlineSites.FullControl.All ApplicationNoYesNoYes
Viva Engageaccess_as_user DelegatedNoNoNoYes
Viva EngageUser_impersonation DelegatedNoNoNoYes