The CIE Enterprise app automatically requests the privileges necessary to
retrieve directory information, user risk information, and any other
additional info you choose to collect. If you enable an option that
requires additional privileges, you must reconnect the directory. For
configurations that use the
CIE Enterprise app,
use the
CIE Enterprise App onboarding URL in step
4.2 to grant the
necessary privileges.
After onboarding the app into Entra ID, you can
revoke privileges if they are
not necessary for your configuration. Do not revoke privileges for
options you select. If you revoke a privilege required for an option you
select or for the Cloud Identity Engine by default, the sync cannot
complete.
To restore revoked permissions, edit the directory configuration and
complete steps
4.1 through
4.5.
The following list provides the permissions for each additional
information type.