Enable Continuous Monitoring
Continuous monitoring connects your environment to Controlio with application (app-only) permissions. You set it up once, and after that your configuration changes are monitored on their own. No agent is installed and nothing is written to your environment.
Prerequisites
| Requirement | Notes |
|---|---|
| Global Administrator | Needed once, to approve the app permissions. Only for the first step. |
| Global Reader role | Microsoft requires it to read Exchange, Teams and Purview configuration. It gives no access to content. See Global Reader Role. |
| License | An active subscription or an ongoing trial. |
Steps
- Click "Enable Continuous Monitoring" in the portal. Microsoft's consent screen opens. A Global Administrator approves once. Every permission is app-only and read-only.
- Assign the Global Reader role. You give the Controlio app the
Global Readerrole in Entra. Reading Email, Teams and Purview configuration depends on this role. Graph consent alone is not enough. - Lock TrueState. Your secure configuration is frozen as the baseline and protection begins.
No access to your content
Controlio reads configuration and security settings, not content. It does not touch your emails, files or messages. Broad permissions such as Sites.FullControl are never requested.
What is read
Controlio evaluates 21 workloads. Fourteen of them work with Graph consent alone. The other seven are on the Exchange side and need Global Reader.
| Surface | Access | Requires |
|---|---|---|
| Entra ID (identities, roles, Conditional Access, PIM) | Graph, read-only | Consent |
| Intune (device and compliance policies) | Graph, read-only | Consent |
| Defender / MDE (security configuration) | Graph, read-only | Consent |
| Exchange, Teams, Purview (configuration) | Exchange Online, read-only | Global Reader |
Next steps
After setup, use TrueState to start protection and VIP Guard to watch critical accounts. You can read why Global Reader is needed on its page.