Permissions

Every permission, by name. And why.

Before you let any tool into a tenant you should be able to read what it asks for. This page lists it all. The permissions are given to an app registration your organization owns, or to your own sign-in; none of them is given to us.

The short version

Four moments, four sets of permissions.

Each one asks only for what that moment needs.

A backup you start

Signs in as you, with delegated read permissions of Microsoft Graph. The app can never read more than your own account may read. Exchange Online, Teams and Power Apps offer no read-only permission, so those three follow your administrator role; during a backup the app only reads.

A scheduled backup

Runs without a person, through a second registration with read permissions, the directory role Global Reader, and a certificate whose private key stays on your computer.

A restore

Signs in on its own, at the moment you confirm the preview, and asks for write permissions for the items you selected and nothing else. The sign-in is discarded afterward.

The one-time setup

Creates the registration in your tenant. It needs two powerful permissions for a few minutes, shows you every line before anything is written, and removes those two from your consent again at the end.

Backups you start: the sign-in registration

The recommended setup creates an app registration named "365 Rewind (sign-in)" in your tenant. It is a public client for a single organization with the redirect address http://localhost. It has no client secret and no certificate, so there is nothing to steal from it: it only works together with a person who signs in. All its permissions are delegated.

You can also skip the setup. The app then signs in through Microsoft's own tools (Quick start), with the same read permissions.

Microsoft Graph, read-only

Every name below is a read permission. The app refuses to put a write permission of Microsoft Graph on this registration; the rule is built in and cannot be switched off. A permission your tenant does not offer, for example one that belongs to a license you do not have, is left out and reported.

  • AccessReview.Read.All
  • AgentIdentityBlueprint.Read.All
  • Agreement.Read.All
  • AppCatalog.Read.All
  • Application.Read.All
  • AttackSimulation.Read.All
  • AuthenticationContext.Read.All
  • BackupRestore-Configuration.Read.All
  • BackupRestore-Control.Read.All
  • BrowserSiteLists.Read.All
  • Channel.ReadBasic.All
  • CloudPC.Read.All
  • ConfigurationMonitoring.Read.All
  • CopilotPackages.Read.All
  • CopilotSettings-LimitedMode.Read
  • CustomAuthenticationExtension.Read.All
  • CustomDetection.Read.All
  • CustomSecAttributeDefinition.Read.All
  • DeviceManagementApps.Read.All
  • DeviceManagementCloudCA.Read.All
  • DeviceManagementConfiguration.Read.All
  • DeviceManagementManagedDevices.Read.All
  • DeviceManagementRBAC.Read.All
  • DeviceManagementScripts.Read.All
  • DeviceManagementServiceConfig.Read.All
  • Directory.Read.All
  • Domain-InternalFederation.Read.All
  • Domain.Read.All
  • EntitlementManagement.Read.All
  • EventListener.Read.All
  • ExternalConnection.Read.All
  • IdentityProvider.Read.All
  • IdentityUserFlow.Read.All
  • LifecycleWorkflows-CustomExt.Read.All
  • LifecycleWorkflows-Workflow.Read.All
  • LifecycleWorkflows.Read.All
  • MultiTenantOrganization.Read.All
  • NetworkAccess.Read.All
  • NetworkAccessPolicy.Read.All
  • OnPremDirectorySynchronization.Read.All
  • Organization.Read.All
  • OrgSettings-AppsAndServices.Read.All
  • OrgSettings-DynamicsVoice.Read.All
  • OrgSettings-Forms.Read.All
  • OrgSettings-Microsoft365Install.Read.All
  • OrgSettings-Todo.Read.All
  • PeopleSettings.Read.All
  • Place.Read.All
  • Policy.Read.All
  • Policy.Read.B2BManagementPolicy
  • Policy.Read.DeviceConfiguration
  • Policy.Read.HybridAuthentication
  • Policy.Read.PermissionGrant
  • PublicKeyInfrastructure.Read.All
  • ReportSettings.Read.All
  • RoleAssignmentSchedule.Read.Directory
  • RoleEligibilitySchedule.Read.Directory
  • RoleManagement.Read.Defender
  • RoleManagement.Read.Directory
  • RoleManagementAlert.Read.Directory
  • RoleManagementPolicy.Read.Directory
  • SearchConfiguration.Read.All
  • SecurityEvents.Read.All
  • SecurityIdentitiesAutoConfig.Read.All
  • SecurityIdentitiesSensors.Read.All
  • SharePointTenantSettings.Read.All
  • Sites.Read.All
  • TeamSettings.Read.All
  • TeamTemplates.Read
  • TeamworkAppSettings.Read.All
  • TermStore.Read.All
  • User.Read
  • User.Read.All

Two of these deserve a note. Sites.Read.All is used for one thing: finding the address of your SharePoint admin center. The app reads no site, list or file. User.Read.All and Directory.Read.All are used to show the names of the people and groups a policy refers to.

Microsoft adds openid, profile and offline_access to every sign-in of a person. They identify you and keep the sign-in alive while the app is open; they are not permissions of an interface.

Services without a read-only permission

Microsoft servicePermissionWhat it allows
Office 365 Exchange OnlineExchange.ManageWhat your Exchange administrator role allows. Also serves Security & Compliance (Defender and Purview policies), which publishes no permission of its own.
Skype and Teams Tenant Admin APIuser_impersonationWhat your Teams administrator role allows.
Power Apps ServiceUserWhat your Power Platform administrator role allows.
Power Platform APIEnvironmentManagement.Environments.Read, EnvironmentManagement.Groups.Read, EnvironmentManagement.Settings.Read, Licensing.BillingPolicies.ReadRead-only.

Microsoft offers no read-only permission for the first three, so they let the app do what the signed-in administrator may do. During a backup the app only reads: it runs the read commands of its settings catalog, which we sign with a key that is kept offline and is not on the portal server. The app verifies that signature with a key built into it before it uses the catalog, and runs only commands of Microsoft's modules for these services. To keep it narrower still, sign in for backups with an account that holds only reader roles.

Scheduled backups: the unattended registration

Scheduled backups are optional. When you switch them on, the app creates a second registration, "365 Rewind (unattended)", for a single organization, with no redirect address and no client secret. It holds:

  • Read permissions of Microsoft Graph as application permissions, for the same settings as above.
  • Exchange.ManageAsApp on Exchange Online and on Security & Compliance. This permission does nothing by itself; what the registration may do there is decided by its role.
  • The directory role Global Reader, which makes that access read-only.
  • One certificate per computer. The key is created on your computer by Windows, cannot be exported and never leaves it; only the public part is sent to the registration.

Some settings can only be read by a signed-in person. A scheduled backup skips them and a backup you start reads them; the coverage page says which.

Restores: write permissions, only then

No write permission of Microsoft Graph is held between restores. When you confirm a restore, the app signs in again and asks for the write permissions of the selected items only: restoring a Conditional Access policy asks for Policy.ReadWrite.ConditionalAccess, not for the right to change Intune. The consent is yours alone, not one for the whole organization, and the sign-in is thrown away when the restore ends.

The one-time setup

Creating a registration needs a person who is a Cloud Application Administrator, an Application Administrator or a Global Administrator. The setup signs in through Microsoft's "Microsoft Graph Command Line Tools" and asks for:

  • Application.ReadWrite.All, to create the registration.
  • DelegatedPermissionGrant.ReadWrite.All, to give it consent for the read permissions.
  • Organization.Read.All and User.Read, to show which tenant and which account you are signed in to.
  • For scheduled backups only: AppRoleAssignment.ReadWrite.All and RoleManagement.ReadWrite.Directory, to give the unattended registration its permissions and the Global Reader role.

Before anything is written you see the plan, line by line: what is created, what is granted, what is kept. You confirm by typing a domain of the tenant. As its last step the setup removes these powerful permissions from your consent on Microsoft's tool again, so they do not linger after the few minutes they were needed.

Taking it all away

In the app, Settings removes each registration with its consents, its role, its certificate and the scheduled task, and shows the same kind of plan first. You can also delete the registrations yourself in the Entra admin center, under App registrations; both carry the tag 365Rewind so they are easy to find. Microsoft keeps a deleted registration restorable for 30 days.

What we hold

Nothing that opens your tenant. No password, token, client secret or certificate ever reaches 365 Rewind, and there is no multi-tenant app of ours to consent to. The security page explains where backups are kept and how they are encrypted.