Proxaradocs
Guides/Connect your systems

Connect Microsoft 365

One admin approval. Mail, calendar, Teams, and files, each read with the signed-in person's own access.

Updated August 2026

About ten minutes, once, for whoever administers Microsoft 365. You need the consent link the firm owner produces in the console's Connect panel, and nothing installs anywhere.

Step 1. Approve it on Microsoft's screen

Microsoft's own screen opens, titled "Permissions requested. Review for your organization". Read the list, then Accept. There is no checkbox: consent is organization-wide by construction.

Microsoft
admin@contoso.com
Permissions requested
Review for your organization
Proxara Connect
Proxara, Inc.
This application is not published by Microsoft or your organization.
This app would like to:
Read user mail
Read user calendars
Read user chat messages
Read user channel messages
Read all files that user can access
Read user's tasks and task lists
Sign in and read user profile
View users' basic profile
If you accept, this app will get access to the specified resources for all users in your organization. No one else will be prompted to review these permissions.
Accepting these permissions means that you allow this app to use your data as specified in their terms of service and privacy statement. You can change these permissions at https://myapps.microsoft.com. Show details
Does this app look suspicious? Report it here
CancelAccept
The consent screen, as the administrator sees it

Every permission is delegated and read-only, and every read carries the signed-in person's own access. Acting in Microsoft 365 is a separate consent, so this approval cannot become a write approval.

Step 2. There is no step 2

Approving switches nothing on. The connection goes live when the first person completes their own Microsoft work sign-in and one real read succeeds.

ClaudeProxara
Get me ready for tomorrow's review with Northgate.
proxara_microsoft_prepare_briefreading Microsoft 3658 records

Three things are open before the [Organization_0599F9C6AF50] review. [Person_0CE2473EA47B] agreed to send the updated schedule by Friday and it has not arrived.

Private brief. Visible to you, never sent to the model.

Three things are open before the Northgate Partners review. Jordan Avery agreed to send the updated schedule by Friday and it has not arrived.

One sign-in, and that is the whole setup

You're done

The owner sees it go live in the console. Nothing comes back to IT.

If something doesn't work

  • Link expired before you opened it? The owner issues a single-use replacement from the same panel.
  • Accepted, but nothing happened? A consent granted in the wrong tenant shows as a visible setup state, not a silent gap.
What IT is not asked to do
Not askedWhat is true instead
Install anythingConnect is hosted. Nothing is packaged or pushed onto anyone's computer.
Trust or distribute a certificateNone is created, and no certificate authority either.
Change the networkThe path runs between the assistant, the firm's own Proxara environment, and Microsoft. Nothing listens inbound.
Store a credentialThe assistant registers itself: no client ID, secret, or token to hold or rotate.
Grant an application permissionEvery permission is delegated, and none of them writes.

A change-advisory board that reviews device, network, or certificate changes will find none of the three here. It is one approval inside Entra.

The permissions, exactly as the screen shows them

Expect one bold line partway down: "This application is not published by Microsoft or your organization." Microsoft shows it for any application it did not publish and the firm did not register. Under the application name, a verified publisher renders as a name in blue with a solid blue badge and white check; an unverified application renders the literal word "unverified" instead.

The screen shows Microsoft's display names; the scope strings appear in the Entra admin center.

What the screen rendersScopeWhy it is requested
Read user mailMail.ReadClient correspondence and attachments
Read user calendarsCalendars.ReadThe meeting or deadline behind a request
Read user chat messagesChat.ReadTeams conversations the employee is in
Read user channel messagesChannelMessage.Read.AllTeam channels the employee belongs to
Read all files that user can accessFiles.Read.AllOneDrive and SharePoint documents
Read user's tasks and task listsTasks.ReadTo Do and Planner items
Sign in and read user profileUser.ReadKnowing which employee is asking
View users' basic profileprofileThe employee's name, for attribution
Sign users inopenidThe standard sign-in permission
Not rendered as a rowoffline_accessRenewal, so nobody signs in every time

ChannelMessage.Read.All is the one Microsoft flags as requiring administrator consent, and that single flag is why an administrator is involved at all. The screen may draw fewer rows than there are scopes: profile is often folded into User.Read.

Where it appears afterwards, and how to take it back out
Where the application appears
Entra ID > Enterprise apps > All applications
Microsoft Entra admin centerSearch resources, services, and docs (G+/)Copilot
Home
Agents
Favorites
Entra ID
Overview
Users
Groups
Devices
Enterprise apps
App registrations
Roles & admins
Overview
Overview
Diagnose and solve problems
Manage
All applications
Private Network connectors
User settings
App launchers
Custom authentication extensions
Security
Conditional Access
Consent and permissions
HomeEnterprise applications
Enterprise applications | All applications
Contoso
New applicationRefreshDownload (Export)Preview infoColumns

View, filter, and search applications in your organization that are set up to use your Microsoft Entra tenant as their Identity Provider.

The list of applications that are maintained by your organization are in application registrations.

Search by application name or object ID
Application type == Enterprise ApplicationsApplication ID starts withAdd filters
5 applications found
NameObject IDApplication IDHomepage URLCreated on
Contoso-app1...aaaaaaa-1111-222...bbbbbbbb-2222-3333...9/16/2024
Proxara Connectcccccccc-4444-555...dddddddd-5555-6666...6/24/2026
Load more
Where its permissions are reviewed and revoked
Proxara Connect > Permissions > Admin consent
Microsoft Entra admin centerSearch resources, services, and docs (G+/)Copilot
Overview
Deployment Plan
Diagnose and solve problems
Manage
Properties
Owners
Roles and administrators
Users and groups
Single sign-on
Provisioning
Self-service
Custom security attributes
Security
Conditional Access
Permissions
Token encryption
Activity
Sign-in logs
Usage & insights
Audit logs
Provisioning logs
Access reviews
Troubleshooting + Support
New support request
HomeEnterprise applications | All applicationsProxara Connect
Proxara Connect | Permissions
Enterprise Application
RefreshReview permissionsGot feedback?
Permissions

Below is the list of permissions that have been granted for your organization. As an administrator, you can grant permissions to this app on behalf of all users (delegated permissions). You can also grant permissions directly to this app (app permissions). Learn more.

You can review, revoke, and restore permissions. Learn more.

To configure requested permissions for apps you own, use the app registration.

Grant admin consent for Contoso
Admin consentUser consent
Search permissions
API NameClaim valuePermissionTypeGranted throughGranted by
Microsoft Graph
Microsoft GraphMail.ReadRead user mailDelegatedAdmin consentAn administrator
Microsoft GraphCalendars.ReadRead user calendarsDelegatedAdmin consentAn administrator
Microsoft GraphChat.ReadRead user chat messagesDelegatedAdmin consentAn administrator
Microsoft GraphChannelMessage.Read.AllRead user channel messagesDelegatedAdmin consentAn administrator
Microsoft GraphFiles.Read.AllRead all files that user can accessDelegatedAdmin consentAn administrator
Microsoft GraphTasks.ReadRead user's tasks and task listsDelegatedAdmin consentAn administrator
Microsoft GraphUser.ReadSign in and read user profileDelegatedAdmin consentAn administrator
Microsoft GraphprofileView users' basic profileDelegatedAdmin consentAn administrator
Microsoft GraphopenidSign users inDelegatedAdmin consentAn administrator
Microsoft Graphoffline_accessMaintain access to data you have given it access toDelegatedAdmin consentAn administrator
Revoke Permission
Revoke Permission
One permission, from its own row on Permissions.
Remove assignment
One assigned user or group, on Users and groups.
Delete
The whole application, on Properties, then Yes.
Permissions on the User consent tab cannot be revoked from the portal. Microsoft requires the Graph API or PowerShell for those.
Where the application appears afterwards, and where it is revoked

In the Microsoft Entra admin center: Entra ID, then Enterprise apps, then All applications.

To do thisGo here
See exactly what is grantedThe application's Permissions page, under Security
Revoke one permissionThe row's "..." menu, then Revoke Permission
Restrict who may use itProperties, set "Assignment required?" to Yes, then assign people under Users and groups
Stop sign-in entirelyProperties, set "Enabled for users to sign-in?" to No
Remove it altogetherProperties, then Delete, then Yes to confirm

Proxara does not poll Microsoft. It uses a stored access token until that token nears expiry, and withdraws a person's access the first time Microsoft refuses a renewal or a read, so a change made in Entra takes effect on the next use. The immediate stop is the owner's own switch in the console: Ending access.

Closing user consent for everything else
HomeConsent and permissions
Consent and permissions | User consent settings
Manage
User consent settings
Admin consent settings
Permission classifications
SaveDiscardGot feedback?

Control when end users and group owners are allowed to grant consent to applications, and when they will be required to request administrator review and approval. Allowing users to grant apps access to data helps them acquire useful applications and be productive, but can represent a risk in some situations if it's not monitored and controlled carefully.

User consent for applications
Configure whether users are allowed to consent for applications to access your organization's data. Learn more
Do not allow user consent
An administrator will be required for all apps.
Allow user consent for apps from verified publishers, for selected permissions
All users can consent for permissions classified as "low impact", for apps from verified publishers or apps registered in this organization.
Let Microsoft manage your consent settings (Recommended)
Automatically update your organization to Microsoft's current user consent guidelines. Learn more
Enable user consent for popular Mail clients
Users can consent to popular applications for specific Mail permissions. List of applications and permissions allowed for user consent are located here.
The user consent setting, if the firm chooses to close it

Optional, and Connect works either way. Left open, an employee can grant an AI tool access to their own mailbox with nobody reviewing it. Closed, only sanctioned applications reach Microsoft Graph.

  1. Entra ID, then Enterprise apps, then Consent and permissions, then User consent settings.
  2. Under "User consent for applications", choose "Do not allow user consent".
  3. Save, from the command row at the top left of the pane.

On the neighbouring Admin consent settings page, turn off "Users can request admin consent to apps they are unable to consent to". An employee who tries one then sees "Need admin approval" and no way forward.

Where to go next

To do thisRead
The next systemConnect Karbon
The whole rolloutWhat happens when you deploy
The one-page version for the approverProxara Connect for IT