HomeDocumentation and Guides
Home

Office365 Scope Categories

Low-Risk Scope Categories

Access Personal Information Scopes

Basic Information Scopes

Azure Active Directory

  • Read all users' basic profiles

MicrosoftGraph

  • Have full access to user calendars
  • Have full access to user shared calendars
  • Have read access to user calendars
  • Have read access to user shared calendars
  • Read all users' basic profiles
  • Read user profiles

Office365ExchangeOnline

  • Have full access to user calendars
  • Have full access to user contacts
  • Have full access to user groups
  • Have full access to user shared contacts
  • Have read access to user contacts
  • Have read access to user mails
  • Have read access to user shared contacts

Office365 SharePoint

  • Read all users' basic profiles
  • Read user profiles

SkypeforBusinessOnline

  • Read all users' basic profiles
  • Read user profiles

Windows Azure Active

  • Read User Profile

Azure Active Directory

  • Enable sign-in and read user profile

MicrosoftGraph

  • Enable sign-in and read user profile

Office365ExchangeOnline

  • View all users profile

Office365 SharePoint

  • Enable sign-in and read user profile

SkypeforBusinessOnline

  • Enable sign-in and read user profile

Medium-Risk Scope Categories

Act on behalf of a user Scopes

Access inbox or contacts information Scopes

Limited Access to Data and Files Scopes

Read Only Access to Data and Files Scopes

adobe

  • Access the adobe application

MicrosoftGraph

  • Access As User
  • Access directory as the signed in user
  • Read all groups (preview)
  • Read and write all groups (preview)
  • Send mail as a user
  • Send shared mail as a user

Office365ExchangeOnline

  • Have full access to user shared tasks
  • Have full access to user tasks
  • Manage exchange configuration
  • Send mail
  • Send mail on behalf of the user
  • Send shared mail

Office365 SharePoint

  • Read and write managed metadata
  • Read managed metadata

OneNote

  • full access to all notes
  • full access to notes on organization

PowerBIService

  • Create content

SkypeforBusinessOnline

  • create meetings
  • Initiate conversations and join meetings
  • Receive conversations

Windows Azure Service Management

  • Access the Yammer platform

MicrosoftGraph

  • Have full access to user contacts
  • Have full access to user shared contacts
  • Have read access to user contacts
  • Have read access to user shared contacts
  • read user's basic profile
  • read user's email address

Office365ExchangeOnline

  • Have full access to a user mailbox
  • Have full access to user contacts
  • View user profile

SkypeforBusinessOnlin

  • Have full access to user contacts
  • Read user contacts

MicrosoftGraph

  • Create pages in user notebooks
  • Have full access to selected user files
  • Have full access to user files
  • Have full access to user mail
  • Have full access to user shared mail
  • Notes full access
  • Read and write user mailbox settings
  • Read and write users notes
  • Read directory data
  • Read directory data (for all users)
  • Read selected files
  • Run search queries as a user
  • Shared tasks full access
    Office365ExchangeOnline
  • Access mailbox settings
  • Have full access to all users mail
  • Have full access to user calendars
  • Have full access to user mail
  • have full access to user profile
  • Have full access to user shared calendars
  • Have full access to user shared mail

Office365 Management APIs

  • Access Management Activity feed
  • Read sites data

Office365 SharePoint

  • Access to service health status
  • Read user files
  • Run search queries as a user
  • Write user files

OneNote

  • Create notes
  • full access to app notes

PowerBIService

  • Alter data
  • Full access to dataset
    WindowsAzureActiveDirectory
  • Read directory data

MicrosoftGraph

  • Have read access to user files
  • Have read access to user mail
  • Have read access to user shared mail
  • Read Identity Risk events
  • Read notes
  • Read people list
  • Read reports
  • Read shared tasks
  • Read tasks

Office365ExchangeOnline

  • Have full access to user people list
  • Have read access to user calendars
  • Have read access to user contacts
  • Have read access to user groups
  • Have read access to user mail
  • Have read access to user people list
  • Have read access to user shared calendars
  • Have read access to user shared mail
  • Have read access to user shared tasks
  • Have read access to user tasks
    Office365ManagementAPIs
  • Read activity feed
  • Read Activity Report
  • Read threatIntelligence data

OneNote

  • Read all notes
  • Read notes

PowerBIService

  • have full access to group data
  • Read dashboard
  • Read dataset
  • Read group data
  • View metadata
  • View reports
    WindowsAzureActiveDirectory
  • Read directory data (all org)

High-Risk Scope Categories

Full Data Access Scopes

Manage User Activity Scopes

Azure Active Directory

  • Read and write users profiles

MicrosoftGraph

  • Edit or delete user files
  • Have full control of all site collections
  • Have read access to app files
  • Read and write directory data
  • Read and write items and lists in all site collections
  • Read and write items in all site collections
  • Read and Write OneNote notebooks
  • Read and Write tasks
  • Read and write users profiles
  • Read items in all site collections
  • Read OneNote notebooks
  • Read user files
  • Write directory data

Office365ExchangeOnline

  • Full access to all mailboxes

Office365 Management APIs

  • Full control access to all sites
  • Manage all sites
  • Write to sites

Office365 SharePoint

  • Read and write items and lists in all site collections
  • Read and write items in all site collections
  • Read and write users profiles
  • Read items in all site collections

SkypeforBusinessOnline

  • Read and write users profiles

Azure Active Directory

  • Read and write user profiles

MicrosoftGraph

  • Access user's data anytime
  • Read and write user profiles

MicrosoftRightsManagementServices

  • Access the MicrosoftRightsManagementServices application

Office365 SharePoint

  • Read and write user profiles

Office365Yammer

  • Access the Office365Yammer application

SkypeforBusinessOnline

  • Read and write user profiles

WindowsAzureActiveDirectory

  • Access As User
  • Access the AD platform
  • Write directory data

##Other—No-Risk Associated
No app permissions