Azure ATP Directory services account rights

I cloud not find documentation on the needed rights for the service account that is defined in Directory services. Can you point me to the document or give instructions on how to setup the correct user rights.



@Jari_L , basically it needs read only access to AD and to it's deleted items.

One some hardened networks it might require more tweaks, but mostly that's it...