Enable Continuous Monitoring
Continuous monitoring connects your environment to Controlio with application (app-only) permissions. You set it up once, and after that your configuration changes are monitored on their own. No agent is installed and nothing is written to your environment.
Prerequisites
| Requirement | Notes |
|---|---|
| Global Administrator | Needed once, to approve the app permissions. Only for the first step. |
| Global Reader role | Microsoft requires it to read Exchange, Teams and Purview configuration. It gives no access to content. See Global Reader Role. |
| License | An active subscription or an ongoing trial. |
Setup wizard
When you open the Continuous Monitoring page in the portal and your setup isn't finished yet, a wizard guides you through it step by step. It always resumes where you left off — if you stop midway and come back later, nothing is lost.
- Consent. You review the access scope and approve; Microsoft's consent screen then opens. A Global Administrator approves once. Every permission is app-only and read-only.
- Activation. After consent, setup completes on its own and monitoring starts. Entra ID, Intune and Defender checks begin collecting right away.
- Global Reader. You assign the
Global Readerrole to the Controlio app in Entra. The Email, Teams and Purview checks and VIP Guard depend on this role; Graph consent alone is not enough. Once you've assigned it, use "I assigned it — check now" to verify immediately, or let the system detect it on its own (within an hour).
When setup is complete the wizard disappears and the normal monitoring panel takes over. As a final step, lock TrueState — your secure configuration is frozen as the baseline and drift protection begins.
Only a Global Administrator can start setup. If you aren't one, the page says so clearly and offers a button to share the link with your administrator. To view monitoring results, the Global Reader, Security Administrator or Security Reader roles are also sufficient.
If you'd rather not assign Global Reader right away, you can continue with "Skip this step for now". Monitoring runs with 14 control areas; the Email, Teams and Purview cards show as "waiting for Global Reader", and coverage expands on its own once you assign the role.
Controlio reads configuration and security settings, not content. It does not touch your emails, files or messages. Broad permissions such as Sites.FullControl are never requested.
What is read
Controlio evaluates 22 workloads. Fourteen of them work with Graph consent alone. The other eight are on the Exchange and Purview side and need Global Reader.
| Surface | Access | Requires |
|---|---|---|
| Entra ID (identities, roles, Conditional Access, PIM) | Graph, read-only | Consent |
| Intune (device and compliance policies) | Graph, read-only | Consent |
| Defender / MDE (security configuration) | Graph, read-only | Consent |
| Exchange, Teams, Purview (configuration) | Exchange Online, read-only | Global Reader |
Next steps
After setup, use TrueState to start protection and VIP Guard to watch critical accounts. You can read why Global Reader is needed on its page.