Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Next »

INKY Enterprise Applications

Each API access request by INKY end up in the Azure AD Enterprise Applications section found here: https://aad.portal.azure.com/#blade/Microsoft_AAD_IAM/StartboardApplicationsMenuBlade/AllApps

There are 5 INKY Enterprise Applications used by INKY though they are not all mandatory.

  • INKY Dashboard SSO (Required if you want to use SSO through AzureAD and INKY Dashboard)

    • Sign users in - Delegated

    • View users' basic profile - Delegated

    • View users’ email address - Delegated

  • INKY Phish Fence - Directory Synchronization - INKY uses the Microsoft Graph API to check your tenant's domain and directory information to help ensure you stay protected. This requires you to log in with an Office 365 or Exchange global administrator account. Note: Once this access is granted, you may use the "Check for Missing Domains" tool under Advanced Config > Domain Information; please report any missing domains to INKY support.

    • Sign in and read user profile - Delegated

    • Read directory data - Application

    • Read domains - Application

  • INKY Phish Fence - Installation - Used during the install process (can be deleted after install)

    • Access directory as the signed in user - Delegated

    • Sign users in - Delegated

    • View users' basic profile - Delegated

    • Maintain access to data you have given it access to - Delegated

  • Inky Phish Fence Remediation - Required if using the remediation features on the INKY Dashboard

    • Read and write mail in all mailboxes - Delegated

  • Inky Phish Fence Service (only used for Phish Finder, not needed if not using Phish Finder)

    • Sign in and read user profile - Delegated

    • Read all users' relevant people lists - Application

    • Read directory data - Application

    • Read all users' full profiles - Application

    • Read mail in all mailboxes - Application

More info about the individual permissions can be found here: https://docs.microsoft.com/en-us/graph/permissions-reference

  • No labels