Read-only by design. Australian by default.
We hold the least access we can and the least data we need. Here's exactly how ID Posture treats your tenant and your data.
Least-privilege access
Read-only Microsoft Graph permissions granted via admin consent, plus optional read-only Azure access for subscription-level checks and Azure resource configuration (databases, networking, Key Vault, storage, and compute, AKS and VMs). No write access, ever.
Australian data residency
Hosted in Microsoft Azure's Australia East region. Scan-derived identity data never leaves Australia.
Tenant isolation
Row-level security enforces per-tenant separation in our database, so one customer's data is never queryable from another's session.
Exactly what we request
These are the Microsoft Graph permissions ID Posture asks for. All application-level and read-only, granted via your Entra admin's consent, never a standing delegated session.
If your organisation also connects its Azure subscriptions, we additionally request read-only Azure Resource Manager access to Azure role (RBAC) assignments at subscription, resource-group, and resource scope, plus, for each optional resource category your organisation chooses to enable, read-only configuration access to Azure SQL Server and databases, Cosmos DB, Azure Cache for Redis/Managed Redis, virtual networks and network security groups, Key Vault, Storage accounts, Azure Kubernetes Service, and virtual machines. See our Product page for what each category checks. We never request write access to any Microsoft 365 or Azure resource.
Read our Privacy Policy for the full detail of what we collect and how long we keep it. Our Data Processing Agreement is available on request.
Security questions or want our documentation? Contact our team.