Skip to main content
Five Steps for Cloud Compliance Readiness·A practical playbook for security teamsDownload

Tenant Permissions

Admin consent covers the Microsoft Graph checks. Exchange Online, Microsoft Purview and Microsoft Fabric read their configuration through their own admin interfaces, which need a directory role and a security group on top of consent. This guide walks through both — all read-only.

Getting Started4 steps~10 minutes

Before you start #

WhatValue
Application nameConfigCobraAPI
Application (client) ID0bb1b007-6bb9-42a5-a4f1-28d14f5a7d25
Role to assignGlobal Reader (read-only across Microsoft 365)
Who can assign the roleGlobal Administrator or Privileged Role Administrator
Who can change Fabric tenant settingsFabric Administrator or Global Administrator
!

Admin consent must already be granted.

ConfigCobraAPI only appears in the Entra pickers after an administrator has accepted the admin consent page during onboarding. If you can't find it, finish Getting started, step 3 first.

  1. Assign the Global Reader role to ConfigCobraAPI

    Global Reader lets ConfigCobra read Exchange Online, Microsoft Purview and the rest of your Microsoft 365 configuration. It cannot change anything.

    1. Sign in to the Microsoft Entra admin center ↗.
    2. Go to Identity → Roles & admins → Roles & admins.
    3. Search for Global Reader and open it.
    4. Click Add assignments, then Select member(s).
    5. Search for ConfigCobraAPI (or paste the client ID 0bb1b007-6bb9-42a5-a4f1-28d14f5a7d25), select it and click Select.
    6. Click Next. Set Assignment type to Active, tick Permanently assigned, enter a justification such as ConfigCobra CIS assessment, and click Assign.

    Or with PowerShell (Microsoft Graph PowerShell SDK):

    Connect-MgGraph -Scopes 'RoleManagement.ReadWrite.Directory','Application.Read.All'
    
    $sp = Get-MgServicePrincipal -Filter "appId eq '0bb1b007-6bb9-42a5-a4f1-28d14f5a7d25'"
    
    New-MgRoleManagementDirectoryRoleAssignment `
      -PrincipalId      $sp.Id `
      -RoleDefinitionId 'f2ef992c-3afb-46b9-b7cf-a126ee74c451' `
      -DirectoryScopeId '/'
  2. Create a security group and add ConfigCobraAPI

    Microsoft Fabric doesn't accept an application directly — it grants admin API access to security groups. This group exists only to hold ConfigCobraAPI.

    1. In the Entra admin center, go to Identity → Groups → All groups and click New group.
    2. Fill in:
      • Group type: Security
      • Group name: ConfigCobra-Access (any name works)
      • Group description: ConfigCobra read-only access to Fabric admin APIs
      • Membership type: Assigned
    3. Under Members, click No members selected, search for ConfigCobraAPI, select it and click Select.
    4. Click Create.

    Or with PowerShell:

    Connect-MgGraph -Scopes 'Group.ReadWrite.All','Application.Read.All'
    
    $sp    = Get-MgServicePrincipal -Filter "appId eq '0bb1b007-6bb9-42a5-a4f1-28d14f5a7d25'"
    $group = New-MgGroup -DisplayName 'ConfigCobra-Access' -SecurityEnabled -MailEnabled:$false `
               -MailNickname 'configcobra-access' `
               -Description 'ConfigCobra read-only access to Fabric admin APIs'
    
    New-MgGroupMember -GroupId $group.Id -DirectoryObjectId $sp.Id
  3. Allow the group to use the read-only Fabric admin APIs

    This lets ConfigCobra read your Microsoft Fabric (Power BI) tenant settings for the Fabric section of the CIS benchmark. The setting is read-only by design.

    1. Open the Fabric admin portal ↗ and select Tenant settings.
    2. Scroll to Admin API settings (or type the setting name into the search box) and expand Service principals can access read-only admin APIs.
    3. Switch the toggle to Enabled.
    4. Under Apply to, choose Specific security groups.
    5. Type ConfigCobra-Access and pick the group you created in step 2.
    6. Click Apply.
    i

    If this setting is already enabled for another group, add ConfigCobra-Access next to the existing group instead of replacing it.

  4. Verify and re-run the assessment

    Role assignments and Fabric tenant settings can take up to an hour to take effect. A scan started too early may still report Exchange Online, Purview or Fabric checks as errors.

    $sp = Get-MgServicePrincipal -Filter "appId eq '0bb1b007-6bb9-42a5-a4f1-28d14f5a7d25'"
    
    # Directory roles held by ConfigCobraAPI — expect "Global Reader"
    Get-MgRoleManagementDirectoryRoleAssignment -Filter "principalId eq '$($sp.Id)'" |
      ForEach-Object { (Get-MgRoleManagementDirectoryRoleDefinition -UnifiedRoleDefinitionId $_.RoleDefinitionId).DisplayName }
    
    # Security groups ConfigCobraAPI belongs to — expect "ConfigCobra-Access"
    Get-MgServicePrincipalMemberOf -ServicePrincipalId $sp.Id |
      ForEach-Object { $_.AdditionalProperties.displayName }

    Once both show up, start a new assessment from the Assessment page ↗. The controls that were tagged Missing Permissions should now be evaluated.

Troubleshooting #

SymptomFix
Exchange Online checks error with “The role assigned to application … isn't supported in this scenario”Global Reader isn't assigned yet, or hasn't propagated. Repeat step 1, wait up to an hour, re-run.
ConfigCobraAPI doesn't appear in the member pickerAdmin consent hasn't been granted in this tenant. Complete onboarding consent first.
Fabric checks still error after step 3Confirm ConfigCobraAPI is a member (not only an owner) of the group, and that the group is listed under the setting's Apply to.
“Add assignments” is greyed outYour account needs Global Administrator or Privileged Role Administrator.
Free trial