Skip to content

Required Microsoft Graph permissions

For the Microsoft application connector to access data in Microsoft Graph, you must grant it the permissions it needs. The following Microsoft Graph permissions are required for all Microsoft 365 connections.

  • AccessReview.Read.All
  • AdministrativeUnit.Read.All
  • Agreement.Read.All
  • AgreementAcceptance.Read.All
  • APIConnectors.Read.All
  • APIConnectors.ReadWrite.All
  • AppCatalog.Read.All
  • Application.Read.All
  • CallRecord-PstnCalls.Read.All
  • CallRecords.Read.All
  • Channel.ReadBasic.All
  • ChannelMember.Read.All
  • ChannelMessage.Read.All
  • ChannelSettings.Read.All
  • Chat.Read.All
  • ChatMember.Read.All
  • ChatMessage.Read.All
  • ConsentRequest.Read.All
  • Device.Read.All
  • DeviceManagementApps.Read.All
  • DeviceManagementConfiguration.Read.All
  • DeviceManagementManagedDevices.PrivilegedOperations.All
  • DeviceManagementRBAC.Read.All
  • DeviceManagementServiceConfig.Read.All
  • Domain.Read.All
  • Files.Read.All
  • Group.Read.All
  • GroupMember.Read.All
  • Member.Read.Hidden
  • OnlineMeetings.Read.All
  • Organization.Read.All
  • People.Read.All
  • Place.Read.All
  • Policy.Read.All
  • Reports.Read.All
  • ServiceHealth.Read.All
  • Team.ReadBasic.All
  • TeamMember.Read.All
  • TeamsActivity.Read.All
  • TeamsAppInstallation.ReadForChat.All
  • TeamsTab.Read.All
  • User.Read
  • User.Read.All
  • UserNotification.ReadWrite.CreatedByApp