Backups you start: the sign-in registration
The recommended setup creates an app registration named "365 Rewind (sign-in)" in your tenant. It is a public client for a single organization with the redirect address http://localhost. It has no client secret and no certificate, so there is nothing to steal from it: it only works together with a person who signs in. All its permissions are delegated.
You can also skip the setup. The app then signs in through Microsoft's own tools (Quick start), with the same read permissions.
Microsoft Graph, read-only
Every name below is a read permission. The app refuses to put a write permission of Microsoft Graph on this registration; the rule is built in and cannot be switched off. A permission your tenant does not offer, for example one that belongs to a license you do not have, is left out and reported.
AccessReview.Read.All
AgentIdentityBlueprint.Read.All
Agreement.Read.All
AppCatalog.Read.All
Application.Read.All
AttackSimulation.Read.All
AuthenticationContext.Read.All
BackupRestore-Configuration.Read.All
BackupRestore-Control.Read.All
BrowserSiteLists.Read.All
Channel.ReadBasic.All
CloudPC.Read.All
ConfigurationMonitoring.Read.All
CopilotPackages.Read.All
CopilotSettings-LimitedMode.Read
CustomAuthenticationExtension.Read.All
CustomDetection.Read.All
CustomSecAttributeDefinition.Read.All
DeviceManagementApps.Read.All
DeviceManagementCloudCA.Read.All
DeviceManagementConfiguration.Read.All
DeviceManagementManagedDevices.Read.All
DeviceManagementRBAC.Read.All
DeviceManagementScripts.Read.All
DeviceManagementServiceConfig.Read.All
Directory.Read.All
Domain-InternalFederation.Read.All
Domain.Read.All
EntitlementManagement.Read.All
EventListener.Read.All
ExternalConnection.Read.All
IdentityProvider.Read.All
IdentityUserFlow.Read.All
LifecycleWorkflows-CustomExt.Read.All
LifecycleWorkflows-Workflow.Read.All
LifecycleWorkflows.Read.All
MultiTenantOrganization.Read.All
NetworkAccess.Read.All
NetworkAccessPolicy.Read.All
OnPremDirectorySynchronization.Read.All
Organization.Read.All
OrgSettings-AppsAndServices.Read.All
OrgSettings-DynamicsVoice.Read.All
OrgSettings-Forms.Read.All
OrgSettings-Microsoft365Install.Read.All
OrgSettings-Todo.Read.All
PeopleSettings.Read.All
Place.Read.All
Policy.Read.All
Policy.Read.B2BManagementPolicy
Policy.Read.DeviceConfiguration
Policy.Read.HybridAuthentication
Policy.Read.PermissionGrant
PublicKeyInfrastructure.Read.All
ReportSettings.Read.All
RoleAssignmentSchedule.Read.Directory
RoleEligibilitySchedule.Read.Directory
RoleManagement.Read.Defender
RoleManagement.Read.Directory
RoleManagementAlert.Read.Directory
RoleManagementPolicy.Read.Directory
SearchConfiguration.Read.All
SecurityEvents.Read.All
SecurityIdentitiesAutoConfig.Read.All
SecurityIdentitiesSensors.Read.All
SharePointTenantSettings.Read.All
Sites.Read.All
TeamSettings.Read.All
TeamTemplates.Read
TeamworkAppSettings.Read.All
TermStore.Read.All
User.Read
User.Read.All
Two of these deserve a note. Sites.Read.All is used for one thing: finding the address of your SharePoint admin center. The app reads no site, list or file. User.Read.All and Directory.Read.All are used to show the names of the people and groups a policy refers to.
Microsoft adds openid, profile and offline_access to every sign-in of a person. They identify you and keep the sign-in alive while the app is open; they are not permissions of an interface.
Services without a read-only permission
| Microsoft service | Permission | What it allows |
| Office 365 Exchange Online | Exchange.Manage | What your Exchange administrator role allows. Also serves Security & Compliance (Defender and Purview policies), which publishes no permission of its own. |
| Skype and Teams Tenant Admin API | user_impersonation | What your Teams administrator role allows. |
| Power Apps Service | User | What your Power Platform administrator role allows. |
| Power Platform API | EnvironmentManagement.Environments.Read, EnvironmentManagement.Groups.Read, EnvironmentManagement.Settings.Read, Licensing.BillingPolicies.Read | Read-only. |
Microsoft offers no read-only permission for the first three, so they let the app do what the signed-in administrator may do. During a backup the app only reads: it runs the read commands of its settings catalog, which we sign with a key that is kept offline and is not on the portal server. The app verifies that signature with a key built into it before it uses the catalog, and runs only commands of Microsoft's modules for these services. To keep it narrower still, sign in for backups with an account that holds only reader roles.
Scheduled backups: the unattended registration
Scheduled backups are optional. When you switch them on, the app creates a second registration, "365 Rewind (unattended)", for a single organization, with no redirect address and no client secret. It holds:
- Read permissions of Microsoft Graph as application permissions, for the same settings as above.
Exchange.ManageAsApp on Exchange Online and on Security & Compliance. This permission does nothing by itself; what the registration may do there is decided by its role.
- The directory role Global Reader, which makes that access read-only.
- One certificate per computer. The key is created on your computer by Windows, cannot be exported and never leaves it; only the public part is sent to the registration.
Some settings can only be read by a signed-in person. A scheduled backup skips them and a backup you start reads them; the coverage page says which.
Restores: write permissions, only then
No write permission of Microsoft Graph is held between restores. When you confirm a restore, the app signs in again and asks for the write permissions of the selected items only: restoring a Conditional Access policy asks for Policy.ReadWrite.ConditionalAccess, not for the right to change Intune. The consent is yours alone, not one for the whole organization, and the sign-in is thrown away when the restore ends.
The one-time setup
Creating a registration needs a person who is a Cloud Application Administrator, an Application Administrator or a Global Administrator. The setup signs in through Microsoft's "Microsoft Graph Command Line Tools" and asks for:
Application.ReadWrite.All, to create the registration.
DelegatedPermissionGrant.ReadWrite.All, to give it consent for the read permissions.
Organization.Read.All and User.Read, to show which tenant and which account you are signed in to.
- For scheduled backups only:
AppRoleAssignment.ReadWrite.All and RoleManagement.ReadWrite.Directory, to give the unattended registration its permissions and the Global Reader role.
Before anything is written you see the plan, line by line: what is created, what is granted, what is kept. You confirm by typing a domain of the tenant. As its last step the setup removes these powerful permissions from your consent on Microsoft's tool again, so they do not linger after the few minutes they were needed.
Taking it all away
In the app, Settings removes each registration with its consents, its role, its certificate and the scheduled task, and shows the same kind of plan first. You can also delete the registrations yourself in the Entra admin center, under App registrations; both carry the tag 365Rewind so they are easy to find. Microsoft keeps a deleted registration restorable for 30 days.
What we hold
Nothing that opens your tenant. No password, token, client secret or certificate ever reaches 365 Rewind, and there is no multi-tenant app of ours to consent to. The security page explains where backups are kept and how they are encrypted.