AuditLog.Read.All |
application |
Access audit log data to check for B2B account auditing |
716a0b19-6f38-4909-a80a-ffaac7957316 |
Channel.Create |
application |
Create channels during provisioning |
716a0b19-6f38-4909-a80a-ffaac7957316 |
Channel.ReadBasic.All |
application |
Read the names and descriptions of all channels during provisioning |
716a0b19-6f38-4909-a80a-ffaac7957316 |
ChannelMember.ReadWrite.All |
both |
Add and remove members from all channels during access review and provisioning |
716a0b19-6f38-4909-a80a-ffaac7957316 |
Directory.ReadWrite.All |
application |
Read and write directory data during Group provisioning |
716a0b19-6f38-4909-a80a-ffaac7957316 |
Group.ReadWrite.All |
both |
Access Microsoft 365 Groups for lifecycle management, whether during scans or for end-users. |
716a0b19-6f38-4909-a80a-ffaac7957316 |
GroupMember.ReadWrite.All |
both |
Access Microsoft 365 Group membership during provisioning and access review. |
716a0b19-6f38-4909-a80a-ffaac7957316 |
InformationProtectionPolicy.Read |
delegated |
Read user sensitivity labels and label policies to apply the appropriate sensitivity labels. |
716a0b19-6f38-4909-a80a-ffaac7957316 |
Mail.Send |
application |
Sends notifications using a shared mailbox. Can be limited to an individual mailbox. |
716a0b19-6f38-4909-a80a-ffaac7957316 |
MailboxSettings.Read |
application |
Reads users' preferred languages for email notifications. |
716a0b19-6f38-4909-a80a-ffaac7957316 |
Notes.ReadWrite.All |
delegated |
Read and write all OneNote notebooks accessible to the user during provisioning. |
716a0b19-6f38-4909-a80a-ffaac7957316 |
Policy.Read.All |
delegated |
Review your organization's policies for B2B invitations. |
716a0b19-6f38-4909-a80a-ffaac7957316 |
Sites.FullControl.All |
both |
Have full control over all site collections for access review and provisioning. |
716a0b19-6f38-4909-a80a-ffaac7957316 |
Tasks.ReadWrite |
application |
Used to read and write tasks for Planner provisioning. |
716a0b19-6f38-4909-a80a-ffaac7957316 |
TeamMember.ReadWrite.All |
both |
Add and remove members from all teams for access review. |
716a0b19-6f38-4909-a80a-ffaac7957316 |
TeamSettings.ReadWrite.All |
both |
Read and change teams' settings during provisioning |
716a0b19-6f38-4909-a80a-ffaac7957316 |
TeamsActivity.Send |
application |
Sends a Teams notification to a user when action is required. |
716a0b19-6f38-4909-a80a-ffaac7957316 |
TeamsAppInstallation.ReadForUser.All |
application |
Used to verify if the Teams app is installed for a user. |
716a0b19-6f38-4909-a80a-ffaac7957316 |
TeamsTab.ReadWrite.All |
application |
Read and write tabs in Microsoft Teams during provisioning. |
716a0b19-6f38-4909-a80a-ffaac7957316 |
User.Read.All |
delegated |
Search for users in your organization using the people picker feature. |
716a0b19-6f38-4909-a80a-ffaac7957316 |
User.ReadWrite.All |
application |
Used for B2B lifecycle management. |
716a0b19-6f38-4909-a80a-ffaac7957316 |
email |
delegated |
View users' email address for SSO |
716a0b19-6f38-4909-a80a-ffaac7957316 |
offline_access |
delegated |
Used for authentication |
716a0b19-6f38-4909-a80a-ffaac7957316 |
openid |
delegated |
Used for authentication and SSO |
716a0b19-6f38-4909-a80a-ffaac7957316 |
profile |
delegated |
Used for authentication and SSO |
716a0b19-6f38-4909-a80a-ffaac7957316 |