Consent and Permissions
Last updated
Last updated
Applications can ask users for permissions to access their data. For example, for basic sign-in. If allowed, a normal user can grant consent only for "Low Impact" permissions. In all other cases, admin consent is required.
The following roles can consent medium- high level impact (whole tenant) permissions:
Global administrator
Application administrator
Cloud application administrator
Custom role including "permission to grant permission to applications"
By default, all users in the tenant can consent to any app to access the organization's data:
One very interesting permission is User.ReadBasic.All
That allows the app to read display name, first and second name, email, open extension and photo for all the users.
This is also a recommendation to tenants that have the default option set: Only consent from verified publishers or do not allow users to consent at all