Entra ID application permissions required by Cayosoft Administrator Service
The Cayosoft Administrator Service requires specific Microsoft Entra ID application permissions to manage your Microsoft 365 tenant and its objects. When you configure Microsoft 365 extension settings, Cayosoft registers Entra ID applications that are used to authenticate, authorize, and perform management operations against Microsoft Graph and other Microsoft 365 services.
Entra ID applications used by Cayosoft Administrator
Cayosoft Administrator uses two Entra ID applications, each with a distinct purpose:
-
The Cayosoft Administrator app that is used for the following purposes:
- Initial Microsoft 365 connection
- Creation of a connection account and creation of a service principal app
- Validation of connection credentials
- MFA detection and configuration checks
- Security defaults / MFA enforcement handling
-
Cayosoft Administrator API Access app that is used in day-to-day operations:
- Rules and workflows
- Web actions
- Reporting
- Automation
- Delegated and self‑service tasks
NOTE: Partial consent is not supported for the Cayosoft Administrator API Access − Single Tenant app. If any required permission is missing, Cayosoft Administrator treats this as a critical error and the connection to Microsoft 365 will not function correctly. A red banner is displayed indicating incomplete consent.
Review granted permissions
Sign in to Entra admin center/ using a Global Administrator account.
Navigate to Enterprise applications > All applications.
Select Cayosoft Administrator.
Click Permissions > User consent.
Additionally, navigate to App registrations > All applications.
Select Cayosoft Administrator API Access − Single Tenant.
Click API permissions.
Cayosoft Administrator application permissions
| Permission | Permission name | Description |
|---|---|---|
| Application.ReadWrite.All | Read and write applications | Allows the app to create, read, update, and delete applications and service principals in Microsoft Entra ID. |
| Directory.ReadWrite.All | Read and write directory data | Used across the product to manage users, groups, and devices. |
| AppRoleAssignment.ReadWrite.All | Manage app permission grants and app role assignments | Allows to manage permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user. |
| RoleManagement.ReadWrite.Directory | Read and write directory RBAC settings | Allows the app to read and manage the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. |
| openid | Sign users in | Allows users to sign in to the app with their work or school accounts and allows the app to see basic user profile information. |
| profile | View users' basic profile | Allows the app to see your users' basic profile (e.g., name, picture, user name, email address) |
| offline_access | Maintain access to data you have given it access to | Allows the app to see and update the data you gave it access to, even when users are not currently using the app. |
Cayosoft Administrator API Access − Single Tenant app delegated/application permissions
The following permissions and roles are granted to the Cayosoft Administrator API Access app and are used across Cayosoft Administrator features.
Assigned roles
| Role | Description |
|---|---|
| Global Administrator | Users with this role have access to all administrative features in Microsoft Entra ID, as well as services that federate to Microsoft Entra ID like Exchange Online, SharePoint Online, and Skype for Business Online. |
| Exchange Administrator | Users with this role have global permissions within Microsoft Exchange Online, when the service is present. |
Microsoft Graph
| Permission | Description |
|---|---|
| AdministrativeUnit.ReadWrite.All | Allows the app to create, read, update, and delete administrative units and manage administrative unit membership without a signed-in user. |
| Application.ReadWrite.OwnedBy | Allows the app to create other applications, and fully manage those applications (read, update, update application secrets and delete), without a signed-in user. |
| AuditLog.Read.All | Allows the app to read and query your audit log activities, without a signed-in user. |
| BitlockerKey.Read.All | Allows an app to read BitLocker keys for all devices, without a signed-in user. Allows read of the recovery key. |
| Calendars.ReadWrite | Allows the app to create, read, update, and delete events of all calendars without a signed-in user. |
| Channel.Delete.All | Delete channels in any team, without a signed-in user. |
| ChannelMember.ReadWrite.All | Add and remove members from all channels, without a signed-in user. Also allows changing a member's role, for example from owner to non-owner. |
| ChannelMessage.Read.All | Allows the app to read all channel messages in Microsoft Teams |
| ChannelSettings.ReadWrite.All | Read and write the names, descriptions, and settings of all channels, without a signed-in user. |
| Device.Read.All | Allows the app to read your organization's devices' configuration information without a signed-in user. |
| Device.ReadWrite.All | Allows the app to read and write all device properties without a signed in user. |
| DeviceLocalCredential.Read.All | Allows the app to read device local credential properties including passwords, without a signed-in user. |
| DeviceManagementManagedDevices.PrivilegedOperations.All | Allows the app to perform remote high impact actions such as wiping the device or resetting the passcode on devices managed by Microsoft Intune, without a signed-in user. |
| DeviceManagementManagedDevices.Read.All | Allows the app to read the properties of devices managed by Microsoft Intune, without a signed-in user. |
| DeviceManagementManagedDevices.ReadWrite.All | Allows the app to read and write the properties of devices managed by Microsoft Intune, without a signed-in user. |
| Directory.ReadWrite.All | Allows the app to read and write data in your organization's directory, such as users, and groups, without a signed-in user. |
| Domain.Read.All | Allows the app to read all domain properties without a signed-in user. |
| Files.Read.All | Allows the app to read all files in all site collections without a signed in user. |
| Group.Create | Allows the app to create groups without a signed-in user. |
| Group.ReadWrite.All | Allows the app to create groups, read all group properties and memberships, update group properties and memberships, and delete groups. Also allows the app to read and write conversations. All of these operations can be performed by the app without a signed-in use |
| GroupMember.ReadWrite.All | Allows the app to list groups, read basic properties, read and update the membership of the groups this app has access to without a signed-in user. |
| GroupSettings.ReadWrite.All | Allows the app to create, read, update, and delete on the list of tenant-level or group-specific group settings objects, without a signed-in user. |
| LicenseAssignment.ReadWrite.All | Allows an app to manage license assignments for users and groups, without a signed-in user. |
| Mail.ReadWrite | Allows the app to create, read, update, and delete mail in all mailboxes without a signed-in user. Does not include permission to send mail. |
| Mail.Send | Allows the app to send mail as any user without a signed-in user. |
| Member.Read.Hidden | Allows the app to read the memberships of hidden groups and administrative units without a signed-in user. |
| Organization.Read.All | Allows the app to read the organization and related resources, without a signed-in user. Related resources include things like subscribed skus and tenant branding information. |
| OrgContact.Read.All | Allows the app to read all organizational contacts without a signed-in user. These contacts are managed by the organization and are different from a user's personal contacts. |
| Policy.ReadWrite.AuthenticationMethod | Allows the app to read and write all authentication method policies for the tenant, without a signed-in user. |
| Reports.Read.All | Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Office 365 and Azure Active Directory. |
| Sites.FullControl.All | Allows the app to have full control of all site collections without a signed in user. Assigned only when Connect to SharePoint Online is enabled. |
| User-LifeCycleInfo.ReadWrite.All | Allows the app to read and write the lifecycle information like employeeLeaveDateTime of users in your organization, without a signed-in user. |
| User-PasswordProfile.ReadWrite.All | Allows the app to read and write password profiles and reset passwords for all users, without a signed-in user. |
| User.DeleteRestore.All | Allows the app to delete and restore all users, without a signed-in user. |
| User.EnableDisableAccount.All | Allows the app to enable and disable users' accounts, without a signed-in user. |
| User.Invite.All | Allows the app to invite guest users to the organization, without a signed-in user. |
| User.Read.All | Allows the app to read user profiles without a signed in user. |
| User.RevokeSessions.All | Allow the app to revoke all sign in sessions for a user, without a signed-in user. |
| UserAuthenticationMethod.ReadWrite.All | Allows the application to read and write authentication methods of all users in your organization, without a signed-in user. Authentication methods include things like a user’s phone numbers and Authenticator app settings. |
Exchange Online management
| Permission | Description |
|---|---|
| Exchange.ManageAsApp | Allows the app to manage the organization's Exchange environment without any user interaction. This includes mailboxes, groups, and other configuration objects. |
Sharepoint Online management
| Permission | Description |
|---|---|
| Sites.FullControl.All | Allows the app to have full control of all site collections without a signed in user. |
| TermStore.ReadWrite.All | Allows the app to write enterprise managed metadata and to read basic site info without a signed in user. |
| User.ReadWrite.All | Allows the app to read and update user profiles and to read basic site info without a signed in user. |
Microsoft Teams management
| Permission | Description |
|---|---|
| TeamSettings.ReadWrite.All | Read and change all teams' settings, without a signed-in user. |
| User.Read.All | Read all users' full profiles |
Notes
-
When you use AD web actions with the Remote Mailbox type, Cayosoft validates the selected UPN suffix against domains available in Microsoft Entra ID. If the suffix does not exist, the following error is displayed:
The domain '@<domain>' is not valid.This behavior is expected and is not related to insufficient permissions.
Change history
| Version | Description |
|---|---|
| 13.2.1 | The article has been updated to feature permissions and roles for the enterprise application and app registration of Cayosoft Administrator in v13.2.1. |
| 11.4.0 | The article has been updated. |
Comments
0 comments
Please sign in to leave a comment.