Skip to main content

Enable Continuous Monitoring

Continuous monitoring connects your environment to Controlio with application (app-only) permissions. You set it up once, and after that your configuration changes are monitored on their own. No agent is installed and nothing is written to your environment.

Prerequisites

RequirementNotes
Global AdministratorNeeded once, to approve the app permissions. Only for the first step.
Global Reader roleMicrosoft requires it to read Exchange, Teams and Purview configuration. It gives no access to content. See Global Reader Role.
LicenseAn active subscription or an ongoing trial.

Setup wizard

When you open the Continuous Monitoring page in the portal and your setup isn't finished yet, a wizard guides you through it step by step. It always resumes where you left off — if you stop midway and come back later, nothing is lost.

  1. Consent. You review the access scope and approve; Microsoft's consent screen then opens. A Global Administrator approves once. Every permission is app-only and read-only.
  2. Activation. After consent, setup completes on its own and monitoring starts. Entra ID, Intune and Defender checks begin collecting right away.
  3. Global Reader. You assign the Global Reader role to the Controlio app in Entra. The Email, Teams and Purview checks and VIP Guard depend on this role; Graph consent alone is not enough. Once you've assigned it, use "I assigned it — check now" to verify immediately, or let the system detect it on its own (within an hour).

When setup is complete the wizard disappears and the normal monitoring panel takes over. As a final step, lock TrueState — your secure configuration is frozen as the baseline and drift protection begins.

If you're not a Global Administrator

Only a Global Administrator can start setup. If you aren't one, the page says so clearly and offers a button to share the link with your administrator. To view monitoring results, the Global Reader, Security Administrator or Security Reader roles are also sufficient.

Leaving Global Reader for later

If you'd rather not assign Global Reader right away, you can continue with "Skip this step for now". Monitoring runs with 14 control areas; the Email, Teams and Purview cards show as "waiting for Global Reader", and coverage expands on its own once you assign the role.

No access to your content

Controlio reads configuration and security settings, not content. It does not touch your emails, files or messages. Broad permissions such as Sites.FullControl are never requested.

What is read

Controlio evaluates 22 workloads. Fourteen of them work with Graph consent alone. The other eight are on the Exchange and Purview side and need Global Reader.

SurfaceAccessRequires
Entra ID (identities, roles, Conditional Access, PIM)Graph, read-onlyConsent
Intune (device and compliance policies)Graph, read-onlyConsent
Defender / MDE (security configuration)Graph, read-onlyConsent
Exchange, Teams, Purview (configuration)Exchange Online, read-onlyGlobal Reader

Next steps

After setup, use TrueState to start protection and VIP Guard to watch critical accounts. You can read why Global Reader is needed on its page.