The following permissions need to be granted to DNS Proxy in your Azure portal:

API

Permission

Microsoft Graph

User.Read.All

Microsoft Graph

Group.Read.All

Microsoft Graph

AuditLog.Read.All

Azure Service Management

user_impersonate

Follow the steps below to grant these API permissions.

  1. Go to your Microsoft Azure Portal.

  2. From the main portal menu in the top left, select Azure Active Directory.

  3. From the Azure Active Directory page, select App registrations from the left-hand menu.

  4. Click on the DNS Proxy app and the app page displays.

  5. From the DNS Proxy app page, select API permissions from the left-hand menu.

  6. Click Add a permission.

  7. On the Request API Permissions page, click Microsoft Graph.

  8. On the Request API Permissions page, click the Application permissions box.

  9. Expand AuditLog and check AuditLog.Read.All.

  10. Expand User and check User.Read.All.

  11. Expand Group and check Group.Read.All.

  12. Click the Add permissions button.

  13. On the Request API Permissions page click Azure Service Management.

  14. Expand Permissions and check user_impersonation.

  15. Click Add permissions.

  16. On the DNS Proxy application > API permissions page, click Grant admin consent.