Microsoft 365

This is the first system an agent changes. Connecting your tenant lets an approved run add somebody to a group, remove them when the period ends, and lets you build the list of what people can ask for by picking real groups instead of typing identifiers. Three permissions, and the only one that changes anything is used after a decision has been made.

What we ask for, and why

User.Read.All
Read the list of people in your tenant, so a request can be for somebody by name and a grant lands on the right account rather than one matched on a display name.
Group.Read.All
Read your groups, so the catalog is built by picking from a list instead of an administrator typing group identifiers into a form.
GroupMember.ReadWrite.All
Add somebody to a group when a request is approved, and remove them when access is revoked. This is the only permission that changes anything.

Nothing here reads mail, files or calendars. The product needs to know who works at your company, what groups exist, and how to add somebody to one.

What the administrator does

  1. Someone with the Global Administrator role opens the consent link. In a small business that is often an outside IT provider, so the link is yours to forward rather than something you have to click yourself.

  2. Microsoft shows the three permissions above and asks them to consent on behalf of the organization.

  3. They land back on the settings page, and the first sync starts on its own. It reports how many people and groups it found.

  4. You pick which of those groups people may request, and who approves each one.

If you disconnect it

Syncing stops and approvals stop changing anything in your directory. Access somebody already has is left alone, because removing it because an integration was disconnected is not what the word promises. Requests carry on being approved and recorded.