API permissions for the Connector for Microsoft 365 and Teams

You must configure the following API permissions in Microsoft Azure to use the Connector for Microsoft 365 and Teams.

Permission Types

The permissions are of the "Delegated" and "Application" types. Actions associated with "Delegated" permissions are performed by a (personal) Microsoft 365 user. The actions associated with "Application" permissions are performed by an Microsoft 365 service account.

Often, the same permission applies to both the "Delegate" and "Application" types. Depending on the use case, it may be desirable for an action to be performed by a regular user or by a service account. Accordingly, you can choose in Intrexx whether Intrexx should log in to Microsoft 365 using a (personal) user account or a service account.

For detailed information on this, see the sections " New Registration - Static User Accounts " and " New Registration - Service Accounts."

Please note that for "Application" permissions, an Entra ID (formerly Azure AD) administrator must grant administrator approval.

API Permissions

API/Permission name

TYPE

Description

Administrator Consent

Calendars.Read Delegated Read Access to User Calendars No
Calendars.Read.Shared Delegated View Users and Shared Calendars No
Calendars.ReadWrite Delegated Has full access to user calendars. No
Calendars.ReadWrite Application Read and write to calendars in all mailboxes Yes
Channel.Create Delegated Create channels Yes
Channel.ReadBasic.All Delegated Read the names and descriptions of the channels No
Channel.ReadBasic.All Usage Read the names and descriptions of all channels Yes
ChannelMessage.Read.All Delegated Read user channel messages Yes
ChannelMessage.Send Delegated Send channel messages No
Chat.Create Delegated Create chats No
Chat.Read Delegated Read user chat messages No
Chat.Read.All Usage Read all chat messages Yes
Chat.ReadBasic Delegated Read the names and members of user chat threads No
Chat.ReadWrite Delegated Read and Write User Chat Messages No
Directory.Read.All Application Read directory data Yes
email Delegated View users' email addresses No
Files.ReadWrite.All Delegated Full access to all files that the user can access No
Group.Create Application Create groups Yes
Group.ReadWrite.All Application Read and write for all groups Yes
GroupMember.Read.All Usage View all group memberships Yes
GroupMember.ReadWrite.All Application Read and write all group memberships Yes
Mail.ReadWrite * Delegated Read and Write Access to User Emails No
Mail.Send * Delegated Sending Emails Under a Different Username No

offline_access

(OpenID Permissions)

Delegated Retain access to data for which you have granted access No
Presence.Read Delegated Read the user's presence information No
Presence.ReadWrite.All * Usage Read and write presence information for all users Yes
profiles Delegated View Basic User Profiles No
Sites.Read.All Delegated Read items in all website collections No
Sites.Read.All Application Read items in all site collections Yes
Sites.ReadWrite.All * Delegated Edit or delete items in all website collections No
Team.Create Delegated Create teams No
Team.Create Application Create teams Yes
Team.ReadBasic.All Delegated Read the names and descriptions of the teams No
Team.ReadBasic.All Application Get a list of all teams Yes
TeamMember.ReadWrite.All Delegated Add and remove members from teams Yes
User.Read.All Application Read all users' full profiles Yes

*optional

Setting API Permissions in Intrexx

In the Connector for Microsoft 365 and Teams, under the "Authentication" menu item, you must specify the permissions (scope) that Intrexx users or Intrexx service accounts should use to access Microsoft 365. You can set the permissions individually there. The individual permissions must be separated by a space.

You can also enter "https://graph.microsoft.com/.default" in the " Connector for Microsoft 365 and Teams." Intrexx users or Intrexx service accounts will then access Microsoft 365 using the permissions you granted at Microsoft Azure.

For detailed information on this, see the " New Registration - Authentication" section.