Integrations & permissions
Last updated: August 20, 2026
Microsoft Entra ID
Sync users and groups
Import Entra users and groups.
OptionalRead-only
- Microsoft Graph application permissions
User.Read.AllGroupMember.Read.All- Access and data
- Reads user IDs, names, email addresses or user principal names, account status, group names, and group memberships. Toolbar does not read mailboxes, files, chats, calendars, or message content.
Sync software and licenses
Import apps, assignments, subscriptions, and seats.
OptionalRead-only
- Microsoft Graph application permissions
Application.Read.AllDirectory.Read.AllOrganization.Read.AllLicenseAssignment.Read.AllSynchronization.Read.All- Access and data
- Reads enterprise applications, delegated permission grants, organization subscription data, license assignments, and synchronization jobs. Toolbar does not create, update, assign, revoke, or delete Microsoft licenses or applications.
Sync usage activity
Use successful account and app sign-ins plus supported Microsoft 365 usage reports to review unused access and suggest software.
OptionalRead-only
- Microsoft Graph application permissions
User.Read.AllAuditLog.Read.AllReports.Read.AllCloudApp-Discovery.Read.All- Access and data
- Authorizes successful account and application sign-in activity, Microsoft 365 usage reports, and existing Defender for Cloud Apps discovery data. Toolbar uses successful sign-in activity and supported Microsoft 365 usage reports. Defender for Cloud Apps discovery access is reserved for future use; Microsoft licensing and tenant configuration determine which sources contain data. Requires Sync software and licenses so activity can be matched to applications and licenses. Toolbar retains the canonical directory user principal name in member identity metadata when available, plus compact activity evidence. It does not retain raw Microsoft 365 report identities or raw sign-in events, IP addresses, locations, devices, risk details, or event IDs. Granting this set does not enable or configure Defender for Cloud Apps discovery.
Manage groups
Edit descriptions, owners, and direct users in synced Entra groups.
OptionalRead and write
- Microsoft Graph application permissions
GroupMember.ReadWrite.AllGroup.ReadWrite.All- Access and data
- Can update group descriptions, add or remove user owners, and add or remove direct users in synced groups after a Toolbar administrator confirms the change. Toolbar does not manage dynamic groups, role-assignable groups, mail-enabled groups, or groups mastered outside Entra.