To run the audit
Read scopes
Your own account, on Graph and Azure in the same tenant.
-
RoleManagement.Read.Directory— Graph, delegated -
Directory.Read.All— Graph, delegated -
Group.Read.All— Graph, delegated -
Application.Read.All— Graph, delegated -
Reader— each subscription, or a management group above them