Global Reader Role
For Controlio to read Exchange Online, Teams and Purview configuration, the app is given the Global Reader role in your tenant. This is a Microsoft rule. The configuration of these services can only be read app-only with Global Reader, and Graph consent does not cover it.
Global Reader is a read-only role. It sees configuration and policy settings. It cannot reach any content, such as a mailbox, file or message, and it cannot change anything.
Why it is needed
Controlio evaluates 21 workloads. Fourteen work with Graph consent alone: Entra, Intune, MDE, sensitivity labels and VIP identity. The other seven are on the Exchange side. They are the Defender for Office anti-phishing, malware, spam and safe-links settings, the VIP mailbox, and the Exchange, Teams and Purview checks. Without Global Reader only this side stays empty. The Graph side keeps working.
How the role is assigned
In the Entra admin center, open Roles and administrators, pick Global Reader and assign it to the Controlio app. In Exchange the role takes effect right away. In Teams it can take a few hours to propagate.
Verification
On the first hourly scan after the role is assigned, the Email, Teams and Purview checks fill in. Controlio checks app-only whether the role is assigned and warns in the portal if it is missing.