Security
Microsoft Online Management Extension relies on the built-in security configuration supported by Microsoft. Every user of MOME will need to log in through Microsoft under their credentials belonging to the same Azure AD tenant.
Users will have to explicitly grant the MOME application the permission to use the Microsoft APIs (the Partner Center API and Graph API) on their behalf.
The Graph API is used to retrieve and modify the following information of the customer and its end-customers for each of the respective customer Microsoft tenants:
-
The total count of users
-
Statistics for license ordering and assignment
-
The Secure Score detail of each end-customer
-
The list of domains
The Graph API is also used to view/list/edit/suspend/reactivate/delete/reset user passwords.
The customer user working with MOME must have either Delegated Admin Privileges (DAP) or Granular Delegated Admin Privileges (GDAP) to the respective customer Microsoft tenant.