API permissions for the Connector for Microsoft 365 and Teams

You must configure the following API permissions in Microsoft Azure to use the Connector for Microsoft 365 and Teams.

Permission Types

The permissions are of the "Delegated" and "Application" types. Actions associated with "Delegated" permissions are performed by a (personal) Microsoft 365 user. The actions associated with "Application" permissions are performed by an Microsoft 365 service account.

Often, the same permission applies to both the "Delegate" and "Application" types. Depending on the use case, it may be desirable for an action to be performed by a regular user or by a service account. Accordingly, you can choose in Intrexx whether Intrexx should log in to Microsoft 365 using a (personal) user account or a service account.

For detailed information on this, see the sections " New Registration - Static User Accounts " and " New Registration - Service Accounts."

Please note that for "Application" permissions, an Entra ID (formerly Azure AD) administrator must grant administrator approval.

API Permissions

In the input field below, you can enter a term to filter the table by.

API/Authorization Name

TYPE

Description

Administrator Consent

Calendars.ReadDelegatedRead Access to User CalendarsNo
Calendars.Read.SharedDelegatedView Users and Shared CalendarsNo
Calendars.ReadWriteDelegatedHas full access to user calendars.No
Calendars.ReadWriteApplicationRead and write to calendars in all mailboxesYes
Channel.CreateDelegatedCreate channelsYes
Channel.ReadBasic.AllDelegatedRead the names and descriptions of the channelsNo
Channel.ReadBasic.AllUsageRead the names and descriptions of all channelsYes
ChannelMessage.Read.AllDelegatedRead user channel messagesYes
ChannelMessage.SendDelegatedSend channel messagesNo
Chat.CreateDelegatedCreate chatsNo
Chat.ReadDelegatedRead user chat messagesNo
Chat.Read.AllUsageRead all chat messagesYes
Chat.ReadBasicDelegatedRead the names and members of user chat threadsNo
Chat.ReadWriteDelegatedRead and Write User Chat MessagesNo
Directory.Read.AllApplicationRead directory dataYes
emailDelegatedView users' email addressesNo
Files.ReadWrite.AllDelegatedFull access to all files that the user can accessNo
Group.CreateApplicationCreate groupsYes
Group.ReadWrite.AllApplicationRead and write for all groupsYes
GroupMember.Read.AllUsageView all group membershipsYes
GroupMember.ReadWrite.AllApplicationRead and write all group membershipsYes
Mail.ReadWrite *DelegatedRead and Write Access to User EmailsNo
Mail.Send *DelegatedSending Emails Under a Different UsernameNo

offline_access

(OpenID Permissions)

DelegatedRetain access to data for which you have granted accessNo
Presence.ReadDelegatedRead the user's presence informationNo
Presence.ReadWrite.All *UsageRead and write presence information for all usersYes
profilesDelegatedView Basic User ProfilesNo
Sites.Read.AllDelegatedRead items in all website collectionsNo
Sites.Read.AllApplicationRead items in all site collectionsYes
Sites.ReadWrite.All *DelegatedEdit or delete items in all website collectionsNo
Team.CreateDelegatedCreate teamsNo
Team.CreateApplicationCreate teamsYes
Team.ReadBasic.AllDelegatedRead the names and descriptions of the teamsNo
Team.ReadBasic.AllApplicationGet a list of all teamsYes
TeamMember.ReadWrite.AllDelegatedAdd and remove members from teamsYes
User.Read.AllApplicationRead all users' full profilesYes

*optional

Setting API Permissions in Intrexx

In the Connector for Microsoft 365 and Teams, under the "Authentication" menu item, you must specify the permissions (scope) that Intrexx users or Intrexx service accounts should use to access Microsoft 365. You can set the permissions individually there. The individual permissions must be separated by a space.

You can also enter "https://graph.microsoft.com/.default" in the " Connector for Microsoft 365 and Teams." Intrexx users or Intrexx service accounts will then access Microsoft 365 using the permissions you granted at Microsoft Azure.

For detailed information on this, see the " New Registration - Authentication" section.