The Azure AD Application needs the following permissions:
API:
Microsoft Graph
Permission Type:
Application
Permissions:
AuditLog.Read.All
DeviceManagementApps.Read.All
DeviceManagementConfiguration.Read.All
DeviceManagementManagedDevices.Read.All
DeviceManagementRBAC.Read.All
DeviceManagementServiceConfig.Read.All
Directory.Read.All
Policy.Read.All
Reports.Read.All