Granting consent
This page walks you through connecting Bus-Factor Report to your Microsoft 365 tenant yourself, without an IT provider. It takes about five minutes. Every step below is checked against Microsoft's own documentation, listed under Sources.
1. Confirm you are a Global Administrator
The permissions we ask for are application permissions, and only certain admin roles can approve those for the whole organization: Global Administrator or Privileged Role Administrator.[3] If you bought your firm's Microsoft 365 subscription yourself, you are a Global Administrator by default.[1]
To check, use either admin center:
- Microsoft 365 admin center (admin.microsoft.com): go to Users > Active users, select your own name, and look under Roles.[1]
- Microsoft Entra admin center (entra.microsoft.com): browse to Entra ID > Roles & admins, then select Your Role to see the roles assigned to you.[2]
If you see Global Administrator, continue. If not, see "Ask your IT provider" below.
2. What the consent screen will show
When you start the connection, Microsoft (not us) shows a sign-in page and then a consent screen. It has these parts:[4]
- A title of "Permissions requested" with a second line, "Accept for your organization". That second line means you are approving for the whole tenant.
- The app name and logo. Microsoft does not validate these, so check the publisher line next.
- The publisher. A verified publisher shows a name with a blue "verified" badge. If it says "Unverified" instead, stop and email us before you accept.
- The list of permissions. Select the arrow next to each one to read Microsoft's description.
You should see exactly these permissions, all read-only, all for Microsoft Graph. Microsoft's label is in bold.[5] If you see anything else, do not accept.
- Read all users' full profiles (User.Read.All). Names, job titles, manager chain, and whether each account is enabled.
- Read all users' basic profiles (User.ReadBasic.All). Display names and email addresses, so group members and owners can be matched to people.
- Read all audit log data (AuditLog.Read.All). Only each user's last sign-in date. Microsoft keeps that date behind this permission.
- Read all group memberships (GroupMember.Read.All). Who belongs to each group, Team, and distribution list, and who owns it where Microsoft shows an owner (distribution lists created in Exchange do not).
- Read all applications (Application.Read.All). Who owns each enterprise app in your tenant.
- Read all directory RBAC settings (RoleManagement.Read.Directory). Who holds admin roles, such as Global Administrator.
- Read items in all site collections (Sites.Read.All). Who owns each SharePoint site. Microsoft's wording covers documents too; we never open files.
- Read basic details of calendars in all mailboxes (Calendars.ReadBasic.All). Organizer, attendees, and title of recurring meetings. Microsoft excludes event bodies, attachments, and extensions from this permission.
- Read basic mail in all mailboxes (Mail.ReadBasic.All). Sender, recipients, date, and thread for the last 90 days. Microsoft excludes bodies and attachments; we also never request subject lines.
We do not ask for any Exchange permission. That is why the report cannot see who owns a shared mailbox and marks it unknown instead. See data handling for the full list of what we read and never read.
3. What "Accept" does and does not do
Accepting records your consent for the whole organization and lets our app use the permissions above without anyone signed in.[3][4]
- It does: let our software read the directory, group, site, calendar, and mail metadata listed above.
- It does not: give us a user account, a password, or a seat in your tenant.
- It does not: let us change, create, or delete anything. Every permission above is a "Read" permission.[5]
- It does not: let us send email as anyone, or read message bodies or attachments.[5]
4. How to revoke access
You can remove the app at any time. You do not need to tell us first.
- Sign in to the Microsoft Entra admin center (entra.microsoft.com).
- Browse to Entra ID > Enterprise apps > All applications.
- Search for Bus-Factor Report and select it.
- In the Manage section of the left menu, select Properties.
- At the top of the Properties pane, select Delete, then Yes.[6]
Microsoft keeps a deleted app in a suspended state for 30 days, during which you could restore it, and then deletes it permanently.[6] If you would rather keep the app listed but withdraw its access, open the app, select Permissions, go to the Admin consent tab, and choose Revoke permission on each entry.[7]
Ask your IT provider
If you are not a Global Administrator, or you have someone who manages Microsoft 365 for you, send them the link to this page. They need the Global Administrator or Privileged Role Administrator role to approve it.[3] Once the app appears in your tenant, they can also review and grant it from the Microsoft Entra admin center under Entra ID > Enterprise apps > the app > Permissions.[3] Nothing on this page requires them to install anything.
Questions: support@therocketshed.com.
Sources
- Assign admin roles in the Microsoft 365 admin center (Microsoft Learn)
- List Microsoft Entra role assignments (Microsoft Learn)
- Grant tenant-wide admin consent to an application (Microsoft Learn)
- Consent experience for applications in Microsoft Entra ID (Microsoft Learn)
- Microsoft Graph permissions reference (Microsoft Learn)
- Delete an enterprise application (Microsoft Learn)
- Review permissions granted to enterprise applications (Microsoft Learn)