Back

For Microsoft 365 administrators

Grant consent for your organisation

If your tenant requires admin approval for third-party apps, or you want to pre-approve OneView so employees are not prompted individually, complete the Microsoft admin-consent flow below. You will review the exact permissions on Microsoft's own consent page.

Microsoft integration is not configured on this deployment.

OneView requests delegated permissions only — it acts as each signed-in user and never with organisation-wide application permissions. Only ChannelMessage.Read.All (Teams channel messages) is marked by Microsoft as requiring admin consent; everything else can normally be consented by users unless your tenant policy says otherwise. See MICROSOFT_PERMISSIONS.md in the deployment documentation for the full matrix.

Permissions you will be asked to approve

Signing in

  • Sign you in

    openid Read-only

    Lets you sign in with your work account.

  • Basic profile

    profile Read-only

    Your name and job title, to personalise your briefing.

  • E-mail address

    email Read-only

    Your work e-mail address, used as your account identifier.

  • Stay connected

    offline_access Read-only

    Keeps your connection alive so OneView can refresh in the background. You can disconnect at any time.

  • Read your profile

    User.Read Read-only

    Read your own user profile (name, title, e-mail).

Outlook mail

  • Read your mail

    Mail.Read Read-only

    Read messages in your own mailbox. OneView cannot send, move or delete mail.

Calendar

  • Read your calendar

    Calendars.Read Read-only

    Read events in your own calendar. OneView cannot create or change events.

Microsoft Teams

  • Read your Teams chats

    Chat.Read Read-only

    Read 1:1 and group chats you are part of. OneView cannot post messages.

  • Read channel messages

    ChannelMessage.Read.All Read-only Admin approval

    Read messages in channels of teams you belong to. Requires approval from your Microsoft 365 administrator.