/
/

How to Use Microsoft Graph API to Pull Compliance Reports Across Multiple Tenants

by Ann Conte, IT Technical Writer
How to Use Microsoft Graph API to Pull Compliance Reports Across Multiple Tenants blog banner image
How to Use Microsoft Graph API to Pull Compliance Reports Across Multiple Tenants blog banner image

Key Points

  • This guide walks you through using Microsoft Graph API to pull Microsoft 365 compliance data across multiple tenants from a single endpoint.
  • Each Azure AD tenant needs its own app registration with Reports.Read.All, AuditLog.Read.All, SecurityEvents.Read.All, and Directory.Read.All permissions, plus admin consent, before Graph API calls will work.
  • The Microsoft Graph PowerShell SDK authenticates with a registered app’s client ID, tenant ID, and secret, then issues Graph API requests to retrieve sign-in logs, security alerts, and retention labels.
  • Storing tenant credentials in a JSON file and looping through them lets IT teams pull and export compliance data from every managed tenant on a recurring schedule instead of logging in manually.
  • Expired client secrets and Microsoft Graph rate limits are the most common points of failure, so proactive secret-rotation alerts and retry logic matter as much as the initial setup.
  • Automation platforms that support PowerShell scripting across managed endpoints can help schedule these Graph API pulls and add device-level context.

Microsoft Graph API security and compliance tools are essential to any enterprise environment. It gives you a unified endpoint where you can access all the audit logs, DLP reports, alert incidents, and retention policies of your organization’s Microsoft 365 accounts.

Using this tool has several key benefits. It can help maintain cross-tenant compliance visibility, automate reports without relying on portal access, give you a secure app-based authentication method, and provide you with easy integrations with SIEM and custom dashboards.

Guide to accessing compliance reports using Microsoft Graph

Before getting started, you first have to configure the application in the Azure AD portal and ensure that it has the necessary permissions. Then, you can connect your account to Microsoft Graph through Windows PowerShell and automatically generate the reports. You also have the option to automate the process using a .JSON file.

GPOs can be utilized to strengthen your security procedures. You can use the Windows Registry to ensure that all policies are consistently applied to all your managed devices. And, in case an error happens, you can use CMD to troubleshoot.

Prerequisites:

  • Azure AD app registration for each tenant (or use Microsoft Lighthouse, necessary for delegated access)
  • You need admin consent granted for the required API scopes.
  • Microsoft 365 E5 Compliance add-on is required for advanced reports.
  • You must have Windows PowerShell, and it should have the Microsoft Graph SDK installed.
  • Optional/preferable: Access to Intune, GPO, and the Windows Registry for endpoint policy validation

The video shows How to Use Microsoft Graph API to Pull Compliance Reports Across Multiple Tenants on screen — a useful reference before navigating and configuring settings.

Step 1: Register an app in Azure for Graph Access

  1. Open the Azure AD portal in your browser.
  2. Go to App Registrations > New Registration.
  3. Name the app you want to register.
  4. Set what account type access to Accounts in this organizational directory only (Contoso only – Single tenant).
  5. Once done, modify the application permissions by clicking Add a permission. This will take you to Microsoft Graph.
  6. Give the following permissions:
    • Reports.Read.All
    • AuditLog.Read.All
    • SecurityEvents.Read.All
    • Directory.Read.All
  7. Click Add Permissions.
  8. Click the button saying Grant admin consent. After this, the application can now read all the user profiles you gave it access to.
  9. Go to Certificates & secrets.
  10. Select Client Secrets > New Client secret.
  11. Fill out the information and follow the prompts. This will serve as the password to the application.
  12. Take note of the application (client) ID, directory (tenant) ID, and the secret value. This will allow you to access the application again in the future.

Repeat or automate this process for each tenant that requires it.

Step 2: Connect to Microsoft Graph in PowerShell

  1. Open the Start Menu and search for Windows PowerShell.
  2. Right-click Windows PowerShell > Run as administrator.
  3. To install Microsoft Graph, type the following command and press Enter:

Install-Module Microsoft.Graph -Scope CurrentUser

Import-Module Microsoft.Graph

  1. To connect using your app credentials, type the following command and press Enter:

Connect-MgGraph -ClientId "APP_ID" -TenantId "TENANT_ID" -ClientSecret (ConvertTo-SecureString "SECRET" -AsPlainText -Force)

Change “APP_ID” to the client ID, “TENANT_ID” to the tenant ID, and “SECRET” to the secret value you generated.

  1. To select the scope, type Select-MgProfile -Name “beta” and press Enter.

You are now connected to Microsoft Graph.

Step 3: Pull compliance reports with the Microsoft Graph API

Once you are logged in to Microsoft Graph in Windows PowerShell, follow these steps:

  1. To retrieve audit logs, type this command and press Enter:

$logs = Invoke-MgGraphRequest -Method GET -Uri "https://graph.microsoft.com/beta/auditLogs/signIns"

  1. To list DLP alerts, type this command and press Enter:

$alerts = Invoke-MgGraphRequest -Method GET -Uri "https://graph.microsoft.com/beta/security/alerts"

  1. To list retention policies, type this command and press Enter:

$policies = Invoke-MgGraphRequest -Method GET -Uri "https://graph.microsoft.com/beta/security/retentionLabels"

  1. To export the data to a .CSV file, type this command and press Enter:

$logs.value | Export-Csv -Path ".\Tenant_AuditLogs.csv" -NoTypeInformation

Repeat this process for each tenant. Log in using their specific credentials.

Optional: Automate cross-tenant reporting

IT administrators can store all tenant credentials in a JSON file. They can run this file to loop through each tenant whenever they need it to connect to each tenant and consolidate the data. They can automatically run this file on a regular schedule using Task Scheduler through their endpoint management tool.

Here’s a sample tenant loop structure:

foreach ($tenant in $tenantList) {

Connect-MgGraph -ClientId $tenant.ClientId -TenantId $tenant.TenantId -ClientSecret $tenant.Secret

$auditData = Invoke-MgGraphRequest -Uri "https://graph.microsoft.com/beta/auditLogs/signIns"

$auditData.value | Export-Csv -Path ".\$($tenant.Name)_Audit.csv" -Append

}

Optional: Use Registry to support reporting context on endpoints

Use Case: Registry keys can be used to ensure that device tagging and reporting labels are consistently applied across all your devices. To do that, follow these steps:

  1. Open the Start Menu and search for Registry Editor to open the program.
  2. Find the corresponding registry key for the application you want to check. For reference, this is a sample registry path and the relevant values inside:

HKEY_LOCAL_MACHINE\SOFTWARE\Contoso\Compliance

    • TenantTag (String) – The value must be “ClientA”.
    • LastAuditSync (String)- The value must be “[Date of last audit sync]”.

Note: You can use scripts to read these tags to include endpoint metadata in Graph-generated reports.

Optional: Use Group Policy for endpoint compliance status

Use Case: Group policies can be used to support enforcement and ensure endpoint compliance, especially for compliance scoring and data sensitivity reporting.

  1. Open the Start Menu and search for Edit Group Policy to open the program.
  2. Navigate to this location: Computer Configuration > Administrative Templates > Windows Components > Data Collection.
  3. Enable the following policies:
    • Enable Allow Telemetry – You should set this to Enhanced or Full as well.
    • Enable Configure commercial ID for device grouping

Optional: Use CMD to validate permissions and connectivity

Use Case: This is useful for on-premise or hybrid environments where endpoints need compliance alignment.

  1. Open the Start Menu and search for Command Prompt.
  2. Right-click Command Prompt > Run as administrator.
  3. To check Internet and Graph-endpoint access, type this command and press Enter:

nslookup graph.microsoft.com

ping graph.microsoft.com

To validate the local agent sync status, type this command and press Enter:

dsregcmd /status

To make sure that the GPO policies have been applied, type this and press Enter:

gpresult /h gpo.html

Quick-Start Guide

NinjaOne can help you use Microsoft Graph API to pull compliance reports across multiple tenants. The NinjaOne platform is designed to simplify working with Microsoft 365 ecosystems, including complex scenarios like multi-tenant compliance reporting. They have specific capabilities to help manage and automate these processes.

  • Compliance Reporting: Pull security and compliance reports across all managed accounts.
  • Automation: Automate report generation and data collection processes.
  • Integration: Seamlessly connects with Microsoft Graph for real-time data access.
  • Scalability: Designed to handle large-scale compliance monitoring across organizations.

Things to look out for

Issue/RiskPotential ConsequencesFix/Reversal
You experience an “Access Denied” error.You can’t access the data you’re looking for.Confirm that admin consent and required API scopes are properly assigned.
You get an empty response.You don’t get the data you’re looking for.Make sure that the tenant has the appropriate licensing and logging enabled.
The client secret expired.You won’t be able to access the data in Microsoft Graph.Set an alert in your endpoint management tool to tell you when secrets are about to expire to avoid this issue.
There is a script error.You won’t be able to pull the reports.Use Try/Catch blocks and verbose logging for error tracing.

Additional considerations when using Microsoft Graph to pull compliance reports

  • Be mindful of rate limits and Microsoft Graph throttling. You may have to retry some actions in some scenarios, especially if you’re pulling up a lot of data.
  • You can reduce complexity by using Azure Lighthouse or cross-tenant access models.
  • Use Azure Key Vault or an encrypted storage solution to store your client secrets.
  • Make sure that only authorized personnel have access to reports that have user-specific data.

NinjaOne services

NinjaOne enhances Graph-based compliance automation through:

  • Cross-Tenant Execution: You can schedule and deploy PowerShell reporting scripts across all managed tenants using the NinjaOne remote PowerShell tool.
  • Central Credential Management: Store Graph API credentials securely and invoke them per tenant in a secure and encrypted storage solution.
  • Alerting and Compliance Dashboards: Integrate report results into customized dashboards and notify on risk thresholds.
  • Endpoint-Level Context: Pull device-specific registry and GPO data to enrich compliance reports through the NinjaOne endpoint management tool.
  • Automated Ticketing: Set alerts when compliance conditions (e.g., audit inactivity or missing retention policy) are detected.

Take advantage of Microsoft Graph for your compliance reports

Microsoft Graph is a powerful tool for automating compliance reporting in an enterprise environment. It gives IT administrators scalable visibility into tenant activity, data protection, and government posture.

Related topics:

FAQs

Basic sign-in and security alert data is available with standard Microsoft 365 licensing, but advanced compliance reports require a Microsoft 365 E5 or E5 Compliance add-on license.

The v1.0 endpoint is stable and supported for production use, while the beta endpoint exposes newer or in-development compliance and security APIs that can change or break without notice. Relying on beta endpoints for scheduled, cross-tenant automation carries an ongoing maintenance risk.

Retention depends on the Microsoft 365 license tier: sign-in logs typically retain 30 days on most plans, extending further with premium Azure AD licensing, and directory audit logs follow similar tiered limits.

Yes. The app registration only needs the specific API permissions granted with admin consent, not a Global Administrator role assigned to a person.

Microsoft Graph throttles requests per app and tenant, returning a 429 status with a Retry-After header when limits are hit. Scripts pulling data across many tenants should implement exponential backoff and retry logic rather than firing requests in a tight loop.

Graph API can automate and consolidate the same underlying data that the Purview portal displays, but Purview remains the system of record for configuring DLP policies, retention labels, and eDiscovery cases.

You might also like

Ready to simplify the hardest parts of IT?