Controlio Security
CONTINUOUS MONITORING
Şeffaflık & İzinlerTransparency & Permissions

E-postalarınızın içeriğine erişemeyiz; bunun için gereken izinleri istemeyiz.We can’t access the contents of your email because we never request those permissions.

Controlio Security, Microsoft 365 güvenlik ayarlarınızı salt-okunur değerlendirir. E-posta içeriğiniz, dosyalarınız, mesajlarınız veya takviminiz için gereken izinleri (Mail.Read, Files.*, EWS full-access) hiç talep etmeyiz; mevcut yetki yapılandırması bu içeriklerin okunmasına izin vermez. Aşağıda aldığımız her izni ve bunu kendi tenant'ınızda nasıl doğrulayacağınızı bulacaksınız.

Controlio Security evaluates your Microsoft 365 security settings read-only. We never request the permissions required for your email content, files, messages or calendar (Mail.Read, Files.*, EWS full-access); the current authorization configuration does not permit reading that content. Below you will find every permission we hold and how to verify it in your own tenant.

Sözümüze güvenmek zorunda değilsiniz. Verdiğiniz izinleri kendi Microsoft yönetim panelinizden görebilir ve istediğiniz zaman denetleyebilirsiniz. Microsoft, Controlio'nun izin verilmeyen API'lere erişmesini teknik olarak engeller.
You don’t have to take our word for it. You can inspect every permission in your own Microsoft admin portal at any time. Microsoft technically prevents Controlio from accessing APIs it has not been granted.

İki farklı yüzey vardırThere are two distinct surfaces

Güvenlik değerlendirmesi için verilerinizin içeriğini değil, güvenlik yapılandırmasını okuruz. Microsoft bu iki erişimi ayrı izinlerle yönetir.

A security assessment reads your security configuration, not the content of your data. Microsoft governs these through separate permissions.

Eriştiğimiz — YapılandırmaWhat we access — Configuration

Ayarlar, politikalar, kim yönetici, kimde mailbox delegasyonu / mailbox seviyesinde forwarding ayarı var, MFA/CA yapılandırması. Hepsi salt-okunur.

Settings, policies, who is an admin, who holds mailbox delegation / mailbox-level forwarding settings, MFA/CA configuration. All of it read-only.

Erişemediğimiz — İçerikWhat we cannot access — Content

E-posta gövdeleri, dosyalar, Teams mesajları, takvim. Bunlar için gereken izinler (Mail.Read, Files.Read, EWS full-access) bizde yok.

Email bodies, files, Teams messages, calendars. The permissions these require (Mail.Read, Files.Read, EWS full-access) are ones we do not have.

Aldığımız izinlerPermissions we hold HEPSİ SALT-OKUNURALL READ-ONLY

Sürekli izleme, oturum açmış bir kullanıcıya ihtiyaç duymayan uygulama izinleriyle çalışır. Giriş ve arayüz için ayrıca sınırlı oturum izinleri kullanılır. İzinlerin tamamı salt-okunurdur; yazma, silme veya tam kontrol yetkisi yoktur.

Continuous monitoring uses application permissions that don’t require a signed-in user. A small set of delegated permissions supports sign-in and the portal. Every permission is read-only; none allows writing, deleting, or full control.

Kimlik & DizinIdentity & Directory
Kullanıcı, grup, rol ve uygulama yapılandırması (kim yönetici, hangi uygulama izinli, hangi domain). Kişisel kimlik verisi minimize edilir ve maskeli tutulur.
User, group, role and application configuration (who is an admin, which apps are permitted, which domains exist). Personal identity data is minimized and stored masked.
Directory.Read.AllUser.Read.AllGroup.Read.AllDomain.Read.AllOrganization.Read.AllApplication.Read.AllRoleManagement.Read.AllAccessReview.Read.AllAgreement.Read.All
Politika & Erişim KontrolüPolicy & Access Control
Conditional Access ve diğer güvenlik politikalarının yapılandırması.
Configuration of Conditional Access and other security policies.
Policy.Read.All
Cihaz Yönetimi (Intune)Device Management (Intune)
Cihaz uyum ve yapılandırma politikaları (cihaz içeriği değil, politika ayarları).
Device compliance and configuration policies (policy settings, not device content).
DeviceManagementConfiguration.Read.AllDeviceManagementManagedDevices.Read.AllDeviceManagementApps.Read.AllDeviceManagementRBAC.Read.AllDeviceManagementServiceConfig.Read.All
Güvenlik & RiskSecurity & Risk
Güvenlik uyarıları, risk sinyalleri ve denetim logları (yapılandırma değişiklik izi — "kim neyi ne zaman değiştirdi").
Security alerts, risk signals and audit logs (the configuration change trail — "who changed what, and when").
SecurityAlert.Read.AllSecurityEvents.Read.AllSecurityIncident.Read.AllIdentityRiskEvent.Read.AllIdentityRiskyUser.Read.AllAttackSimulation.Read.AllAuditLog.Read.AllReports.Read.All
Bilgi Koruma & SharePointInformation Protection & SharePoint
Hassasiyet etiketi politikaları ve SharePoint tenant paylaşım ayarları. Dosya/site içeriği DEĞİL; SharePoint'te tam-kontrol (FullControl) izni bilinçli olarak alınmaz.
Sensitivity label policies and SharePoint tenant sharing settings. NOT file/site content; the SharePoint full-control (FullControl) permission is deliberately not taken.
InformationProtectionPolicy.Read.AllSensitivityLabels.Read.AllSharePointTenantSettings.Read.All
Exchange (salt-okunur yönetim)Exchange (read-only management)
Exchange.ManageAsApp, uygulamanın kullanıcı oturumu olmadan Exchange Online yönetim API'sine bağlanması için kullanılır; tek başına mailbox veya mesaj içeriği okuma yetkisi vermez. Uygulamanın gerçekleştirebildiği işlemler ayrıca atanmış Exchange RBAC rolleriyle sınırlanır. Mevcut yapılandırmada uygulama salt-okunur Exchange yönetim rollerine (Global Reader) sahiptir ve şu yönetim yapılandırmalarını okur: anti-phishing / anti-malware / anti-spam politikaları, mailbox seviyesindeki forwarding ayarları (ForwardingAddress / ForwardingSmtpAddress) ve yetkili cmdlet'lerin desteklediği mailbox delegasyon bilgileri. Global Reader tek başına, kullanıcıların oluşturduğu Inbox forwarding kurallarını okumaya yetkili değildir.
Exchange.ManageAsApp is used so the application can connect to the Exchange Online management API without a user session; on its own it grants no right to read mailbox or message content. What the application can actually do is additionally limited by its assigned Exchange RBAC roles. In the current configuration the application holds read-only Exchange management roles (Global Reader) and reads the following management configuration: anti-phishing / anti-malware / anti-spam policies, mailbox-level forwarding settings (ForwardingAddress / ForwardingSmtpAddress) and the mailbox delegation information supported by the authorized cmdlets. Global Reader by itself is not authorized to read user-created Inbox forwarding rules.
Exchange.ManageAsApp · Global Reader (View-Only Organization Management)
Oturum (giriş & arayüz)Sign-in (login & portal UI)
Yalnızca giriş yapmanız ve arayüzde kullanıcı araması (ör. VIP seçimi) / kuruluş bilgisi için. Hepsi salt-okunur, kişisel içerik değil.
Only for signing you in and for in-portal user search (e.g. VIP selection) / organization info. All read-only, no personal content.
User.Read (giriş)(sign-in)User.Read.AllDirectory.Read.AllOrganization.Read.All

Hiçbir koşulda erişilmeyenNever accessed, under any circumstances

Aşağıdaki izinler hiç talep edilmez; teknik olarak erişilemez.

The permissions below are never requested; access is technically impossible.

Kendiniz doğrulayın — adım adımVerify it yourself — step by step

Bizim sözümüze değil, kendi Microsoft ortamınıza bakın. Aşağıdakiler sizin tenant'ınızda birkaç dakikada tamamlanır; hiçbir soru işareti bırakmaz. İki yol: portalda tıklayarak veya PowerShell ile kesin doğrulama.

Do not take our word for it — look at your own Microsoft environment. The steps below take a few minutes in your tenant and leave no question marks. Two paths: clicking through the portal or definitive verification with PowerShell.

A) Portalda (tıklama, ~3 dakika)A) In the portal (clicking, ~3 minutes)
İzin listesini görün. portal.azure.comMicrosoft Entra IDEnterprise applications → arama kutusuna Controlio Continuous Monitoring yazıp tıklayın → sol menü Security → PermissionsAdmin consent sekmesi. Verilen TÜM izinler burada listelidir. Kontrol: hepsi ...Read / .Read.All; listede Mail.Read, Mail.ReadWrite, Files.*, Sites.Read/ReadWrite veya full_access_as_app yoktur.
See the permission list. portal.azure.comMicrosoft Entra IDEnterprise applications → type Controlio Continuous Monitoring in the search box and open it → left menu Security → PermissionsAdmin consent tab. ALL granted permissions are listed there. Check: every one is ...Read / .Read.All; the list contains no Mail.Read, Mail.ReadWrite, Files.*, Sites.Read/ReadWrite or full_access_as_app.
Salt-okunur rolü doğrulayın. Microsoft Entra IDRoles and administratorsGlobal ReaderAssignments. Controlio uygulamasını listede görün. Global Reader, Microsoft'un tanımıyla yazma/silme yapamaz; Exchange'de View-Only Organization Management'a karşılık gelir.
Verify the read-only role. Microsoft Entra IDRoles and administratorsGlobal ReaderAssignments. Find the Controlio application in the list. By Microsoft's definition Global Reader cannot write or delete; in Exchange it corresponds to View-Only Organization Management.
Ne eriştiğimizi görün. Aynı uygulama sayfasında Sign-in logs (Service principal sign-ins) → ya da Entra ID → Monitoring → Audit logs. Uygulamanın erişim geçmişini görün — yalnızca yapılandırma okumaları.
See what we access. On the same application page, Sign-in logs (Service principal sign-ins) → or Entra ID → Monitoring → Audit logs. Review the application's access history — configuration reads only.
Onay ekranı. Bir yönetici onay verdiğinde Microsoft'un gösterdiği izin listesi kesin kaynaktır — bizim iddiamız değil, Microsoft'un.
The consent screen. When an admin grants consent, the permission list Microsoft displays is the authoritative source — Microsoft's claim, not ours.
B) PowerShell ile (kesin doğrulama — teknik ekip / denetçi)B) With PowerShell (definitive verification — tech team / auditor)
Uygulamanın Exchange'de hangi rollere sahip olduğunu ve o rollerin hangi cmdlet'leri içerdiğini gösterir (yazma cmdlet'i var mı?):
Shows which roles the application holds in Exchange and which cmdlets those roles contain (any write cmdlets?):
# Exchange Online PowerShell'e yonetici olarak baglanin
Connect-ExchangeOnline

# 1) Uygulamanin Exchange rol atamalari (salt-okunur mu?)
Get-ManagementRoleAssignment -RoleAssignee "Controlio Continuous Monitoring"

# 2) Atanan rolun icerdigi cmdlet'ler — Set-/New-/Remove- var mi?
Get-ManagementRoleEntry "<atanan-rol>\*"

# 3) Delegasyon okumasi gercekte ne dondurur (istege bagli test)
Get-EXOMailboxPermission  -Identity test@firmaniz.com
Get-EXORecipientPermission -Identity test@firmaniz.com
Get-EXOMailbox -Identity test@firmaniz.com -Properties GrantSendOnBehalfTo
# Connect to Exchange Online PowerShell as an admin
Connect-ExchangeOnline

# 1) The app's Exchange role assignments (read-only?)
Get-ManagementRoleAssignment -RoleAssignee "Controlio Continuous Monitoring"

# 2) Cmdlets contained in the assigned role — any Set-/New-/Remove-?
Get-ManagementRoleEntry "<assigned-role>\*"

# 3) What a delegation read actually returns (optional test)
Get-EXOMailboxPermission  -Identity test@yourcompany.com
Get-EXORecipientPermission -Identity test@yourcompany.com
Get-EXOMailbox -Identity test@yourcompany.com -Properties GrantSendOnBehalfTo
Graph tarafında uygulamanın gerçekte sahip olduğu tüm izinleri listeler — mail/dosya/içerik izni var mı?
On the Graph side, lists every permission the application actually holds — any mail/file/content permission?
# Microsoft Graph PowerShell
Connect-MgGraph -Scopes "Application.Read.All"
$sp = Get-MgServicePrincipal -Filter "displayName eq 'Controlio Continuous Monitoring'"
Get-MgServicePrincipalAppRoleAssignment -ServicePrincipalId $sp.Id |
  Select-Object ResourceDisplayName, AppRoleId
Beklenen sonuç: hiçbir çıktıda Mail.Read, Mail.ReadWrite, Mail.ReadBasic.All, full_access_as_app, EWS, Exchange Application Mail.Read veya eDiscovery / Compliance Search izni bulunmaz; Exchange rolleri yalnızca görüntüleme cmdlet'leri içerir.
Expected result: no output contains a Mail.Read, Mail.ReadWrite, Mail.ReadBasic.All, full_access_as_app, EWS, Exchange Application Mail.Read or eDiscovery / Compliance Search permission; the Exchange roles contain view cmdlets only.
Dürüst not (denetim için): Uygulamaya Microsoft Graph Mail.Read/Mail.ReadWrite, EWS full_access_as_app, Exchange Application Mail.Read veya Purview eDiscovery / Compliance Search erişimi verilmemiştir. Bu nedenle mevcut yetki yapılandırması mesaj gövdesi, MIME içeriği veya eklerin okunmasına izin vermez. Sertifika sahibi uygulama yalnızca kendisine verilmiş mevcut yetkileri kullanabilir; sonradan yeni bir izin/rol eklenirse kapsam değişebileceğinden bu durum API izinleri ve Exchange/Purview rol atamaları üzerinden düzenli olarak doğrulanmalıdır.
Honest note (for audit): The application has not been granted Microsoft Graph Mail.Read/Mail.ReadWrite, EWS full_access_as_app, Exchange Application Mail.Read or Purview eDiscovery / Compliance Search access. The current authorization configuration therefore does not permit reading message bodies, MIME content or attachments. The certificate-holding application can only exercise the authorizations it has actually been granted; since scope could change if a new permission/role were added later, this state should be verified regularly via the API permissions and the Exchange/Purview role assignments.

Güven temelleriFoundations of trust

Publisher verified (Microsoft doğrulamalı yayıncı)Publisher verified by Microsoft
Salt-okunur — yazma/silme/full-control yokRead-only — no write/delete/full-control
KVKK uyumlu — kimlik verisi maskeli, tam listeler saklanmazPrivacy-compliant (KVKK/GDPR) — identity data masked, no full lists stored