Skip to content

Permissions

Rick Van Rousselt edited this page Mar 19, 2017 · 3 revisions

Azure Active Directory App permissions

The following permissions are configured in the SPAdminBot.

Add the Microsoft Graph:

  • Read files in all site collections (preview)
  • Read and write files in all site collections (preview)
  • Read files that the user selects (preview)
  • Read and write files that the user selects (preview)
  • Have full access to the application's folder (preview)
  • Read all usage reports
  • Edit or delete items in all site collections
  • Sign in and read user profile
  • Read all users' basic profiles
  • Read all users' full profiles
  • Read and write all users' full profiles
  • Read directory data
  • Read and write directory data
  • Access directory as the signed in user
  • Read user contacts
  • Have full access to user contacts
  • Read user files
  • Read all files that user can access
  • Read items in all site collections
  • Sign users in
  • Access user's data anytime

Add Office 365 SharePoint Online (Microsoft.SharePoint)

Application Permissions

  • Read user profiles
  • Read and write user profiles
  • Read and write managed metadata
  • Read managed metadata
  • Read and write items and lists in all site collections
  • Have full control of all site collections
  • Read items in all site collections
  • Read and write items in all site collections Delegated Permissions
  • Requires admin
  • Read user profiles
  • Read and write user profiles
  • Read and write user files
  • Read user files
  • Have full control of all site collections
  • Read and write items and lists in all site collections
  • Read and write items in all site collections
  • Read items in all site collections
  • Run search queries as a user
  • Read and write managed metadata
  • Read managed metadata

Windows Azure Active Directory (Microsoft.Azure.ActiveDirectory)

  • Sign in and read user profile