Gitbit Report Permissions: What Is Required & Why (Security Guide)

Profile image of John Gruber
Written by John Gruber Published Jul 22, 2026 Updated Jul 22, 2026

When you run a Microsoft 365 license audit report with Gitbit, the application requests specific permissions to connect with Microsoft Graph.

Screenshot showing the exact permissions required to run a Gitbit report

Because we prioritize your security, Gitbit requests minimal permissions. Gitbit cannot make changes to your user accounts, delete files, access emails, or modify license assignments.

Required Permissions and Why They Are Needed

Below is the breakdown of the exact permissions Gitbit requests and the technical reasons why each is required to generate your optimization report:

1. Read Audit Log Data (AuditLog.Read.All)

2. Maintain access to data you have given it access to (offline_access)

3. Read Organization Information (Organization.Read.All)

4. Read All Usage Reports (Reports.Read.All)

5. Read and Write Admin Report Settings (ReportSettings.ReadWrite.All)

6. Sign You In and Read Your Profile (User.Read)

7. Read All Users' Full Profiles (User.Read.All)

Security & Peace of Mind

No Write Access: Gitbit does not ask for permission to write or delete anything in your environment. Once you receive your report, any license adjustments or account disablements must be done manually by your admin in the Microsoft 365 Admin Center.

How to Revoke Gitbit Access

If you want to remove Gitbit's access after running your audit, you can easily clean up the connection inside your tenant:

  1. Open your Microsoft Entra admin center.
  2. Navigate to Identity > Applications > Enterprise applications.
  3. Search for and click on Gitbit.
  4. Go to Properties and click Delete.

Want to stay up-to-date with Microsoft? Follow our Substack