Use Microsoft Graph API to Pull Multi-Tenant Compliance Reports Microsoft Graph API is a critical tool for modern IT and security teams. It provides a unified endpoint to access audit logs, DLP reports, security alerts, and retention policies across Microsoft 365 environments. In this video, we'll walk through how to use Microsoft Graph API to pull compliance reports across multiple tenants. Before we begin, be sure to subscribe to NinjaOne’s IT video hub and our YouTube channel for more tech content like this. Why Use Microsoft Graph for Compliance? First things first, why use Microsoft Graph for compliance reporting? Well, it offers several key benefits. Centralized, cross-tenant compliance visibility Automated reporting without relying on portal access. Secure, app-based authentication and easy integration with SIEM tools and custom dashboards For organizations managing multiple Microsoft 365 tenants, Graph helps scale compliance monitoring without adding operational overhead. Prerequisites to Accessing Compliance Reports Using Microsoft Graph Before you begin using Microsoft Graph to pull compliance reports, make sure you meet the following requirements An Azure AD app registration for each tenant (or delegated access using Microsoft Lighthouse, if applicable) Admin consent for the required Microsoft Graph API scopes Microsoft 365 E5 compliance add on required for advanced reports. Windows PowerShell with the Microsoft Graph SDK installed. Optional access to Intune, Group Policy, and the Windows Registry for endpoint policy validation. Once you're all set, the first thing you need to do is register an Azure AD app for Microsoft Graph access. How to Use Microsoft Graph API to Pull Multi-Tenant Compliance Reports Step 1 — Register an App in Azure for Graph Access Start by opening the Azure AD portal, then navigate to App Registrations and select New Registration. Name your application. set the account type to “Accounts in this organizational directory only (Single tenant),” and complete the registration process. Next, to configure permissions, go to API Permissions and add permissions from Microsoft Graph. Then assign the following Microsoft Graph application permissions. Reports.Read.All AuditLog.Read.All SecurityEvents.Read.All Directory.Read.All Once they’re added, click “Grant admin consent” to enable access. Finally, create a client secret under Certificates & Secrets. Make sure to securely store the Client ID, Tenant ID, and Secret Value for later. Repeat or automate this process for each tenant. Step 2 — Connect to Microsoft Graph Using PowerShell The next step is connecting to Microsoft Graph using PowerShell. First, open PowerShell as an administrator. Next, install and import the Microsoft Graph module using this command To connect using your app credentials, run the following script and make sure to replace "APP_ID", "TENANT_ID", and "SECRET" with the appropriate values. When you're done, switch to the beta profile to access compliance endpoints by running. Select-MgProfile -Name "beta" Step 3 — Pull Compliance Reports With Graph connected, you can now retrieve compliance data. Simply run any of these commands to retrieve audit logs, list DLP alerts, list retention policies, or export the data to a .csv file. Repeat this process for each tenant using their respective credentials. Overall, Microsoft Graph is a powerful tool for automating compliance reporting across Microsoft 365 tenants. With the right configuration, automation, and endpoint context, IT administrators gain scalable visibility into security, posture, data protection, and compliance. For more information, check out our official blog post on Pulling multi-tenant compliance reports using Microsoft Graph Linked in the description below.