> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gc.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect Microsoft 365

> Admin consent, Graph permissions, and security answers for Outlook, Teams, OneDrive, SharePoint, and OneNote

Microsoft 365 covers Outlook, Teams, OneDrive, SharePoint, and OneNote. These apps share one Microsoft Entra app. A tenant admin grants consent once. After that, each person connects their own Microsoft account in GC AI. GC AI then acts with that person's existing Microsoft access. It does not receive tenant-wide application access that bypasses the user's permissions.

<Note>
  Microsoft lists every Graph permission on GC AI's app in one pass, not one list per connector. After you accept, the same Graph names appear in Entra under **Enterprise applications → GC AI → Permissions → Admin consent**.
</Note>

## Grant tenant admin consent (admins)

<Steps>
  <Step title="Start the connect flow">
    Open **Settings → Integrations → Agent Connectors** and select **Connect** on a Microsoft 365 app (Outlook, Teams, OneDrive, SharePoint, or OneNote).
  </Step>

  <Step title="Send or complete the approval">
    The connect dialog says Microsoft requires a one-time admin approval. Use **Copy approval link** and send it to your Microsoft 365 admin, or select **Approve now** if you have that role.
  </Step>

  <Step title="Accept Microsoft's consent screen">
    Complete Microsoft's admin consent screen. Compare the Graph names on that screen to the tables below.
  </Step>
</Steps>

Org admins then set each connector to **Disabled**, **Read-only**, or **Full access** under **Settings → Policies**. Under a connected app, expand **Tools** to set each action to **Always allow**, **Needs approval**, or **Block**. Tools are grouped as **Read** (defaulting to **Always allow**) and **Write & delete** (defaulting to **Needs approval**). See [Agent Connectors](/guides/organizations/agent-connectors#control-what-gc-ai-can-do).

## Connect your account

After admin consent is in place, each person connects their own account:

1. Open **Settings → Integrations → Agent Connectors**.
2. Select **Connect** on the Microsoft 365 app you want.
3. Complete Microsoft's sign-in flow for your account.

Admins cannot connect Outlook, Teams, OneDrive, SharePoint, or OneNote on your behalf. You authorize your own account.

Most organizations see Microsoft SharePoint in Settings. If you do not, contact your GC AI account team. Admin consent is for the shared Microsoft app, so SharePoint Graph permissions can still appear on Microsoft's screen even when the SharePoint tile is hidden.

## What ".All" means on delegated scopes

Scopes such as `Sites.Read.All` and `ChannelMessage.Read.All` are **delegated**. GC AI can reach only the sites, files, chats, and teams the signed-in user can already open in Microsoft 365. `.All` means all of that user's existing access, not application-only access to the whole tenant.

## Permission justifications

These are the delegated Microsoft Graph permissions GC AI requests for Microsoft 365 connectors. The first column is the Graph name you see in Entra. The line under it is the label Microsoft shows on the consent screen.

<AccordionGroup>
  <Accordion title="Shared sign-in">
    | Permission | GC AI feature | Why this access level |
    | - | - | - |
    | `openid` <br /> Sign you in | Microsoft sign-in | Standard OpenID Connect scope for the Microsoft sign-in flow. |
    | `offline_access` <br /> Maintain access to data you have given it access to | Persistent connection | Standard OAuth scope so you are not prompted to sign in on every session. It does not expand data access beyond the other granted scopes. |
    | `User.Read` <br /> Sign in and read user profile | Connected-account identity | Reads the signed-in user's name and email so GC AI can show which Microsoft account is connected. It does not grant directory-wide user access. |
  </Accordion>

  <Accordion title="Microsoft Outlook">
    | Permission | GC AI feature | Why this access level |
    | - | - | - |
    | `Mail.Read` <br /> Read user mail | Search and retrieve email | Users search mail and bring messages into chat for context. Read-only for message content. |
    | `Mail.ReadWrite` <br /> Read and write access to user mail | Create and manage drafts | Required to create and update drafts in the user's mailbox. Broader than read. Sending mail uses `Mail.Send`. |
    | `Mail.Send` <br /> Send mail as a user | Send email | Required to send mail as the user. Users can set send to **Needs approval** or **Block** in GC AI. |
    | `Calendars.Read` <br /> Read user calendars | View schedule | Read-only calendar access for upcoming meetings and context. |
    | `Calendars.ReadWrite` <br /> Have full access to user calendars | Create or update meetings | Read alone cannot create or update events. ReadWrite is required for scheduling actions on the user's behalf. |
    | `Contacts.Read` <br /> Read user contacts | Contact lookup | Read-only. Used to resolve people the user already has in contacts when drafting email or scheduling. GC AI does not create, edit, or delete contacts. |
    | `MailboxSettings.Read` <br /> Read user mailbox settings | Timezone and locale | Read-only mailbox settings so dates and times display correctly for the user. GC AI does not change mailbox settings. |
  </Accordion>

  <Accordion title="Microsoft OneDrive">
    | Permission | GC AI feature | Why this access level |
    | - | - | - |
    | `Files.Read.All` <br /> Read all files that user can access | Browse, search, and open files | Lets users pull OneDrive files they can already open, including files shared with them, into GC AI for review and analysis. |
    | `Files.ReadWrite.All` <br /> Have full access to all files user can access | Upload or save generated documents | Required when a user asks GC AI to save an output back to OneDrive (the Upload file tool). Read alone cannot write files. Access stays limited to drives and files that user can already modify. |

    If your Entra **Admin consent** tab also lists `Files.Read` and `Files.ReadWrite`, those are the original OneDrive file scopes. They cover the signed-in user's own files. The OneDrive connector now requests `Files.Read.All` and `Files.ReadWrite.All`.
  </Accordion>

  <Accordion title="Microsoft SharePoint">
    | Permission | GC AI feature | Why this access level |
    | - | - | - |
    | `Sites.Read.All` <br /> Read items in all site collections | List sites, search libraries, retrieve documents | Delegated: limited to sites and files the signed-in user can already open in SharePoint. Required for site discovery and document search in chat. |
    | `Sites.ReadWrite.All` <br /> Read and write items in all site collections | Upload files; create Word docs; edit Excel in libraries | Write counterpart to `Sites.Read.All`. Same delegated boundary: only sites and libraries the user can already modify in Microsoft 365. Org admins can set Microsoft SharePoint to **Read-only** in **Settings → Policies** to disable write tools. |
    | `Files.ReadWrite.All` <br /> Have full access to all files user can access | Files across drives the user can access, including libraries | `Files.ReadWrite` covers the signed-in user's OneDrive. `Files.ReadWrite.All` is the Graph scope used when reading or writing files in SharePoint libraries and other drives the user can already access, including files shared with them. |
    | `Files.ReadWrite` <br /> Have full access to user files | Create and edit Word and Excel in libraries | Used by SharePoint document-edit tools (create a Word doc, edit Excel). Complements the Sites and Files.All scopes above. |
  </Accordion>

  <Accordion title="Microsoft Teams">
    | Permission | GC AI feature | Why this access level |
    | - | - | - |
    | `Team.ReadBasic.All` <br /> Read the names and descriptions of teams | List teams the user belongs to | Read team names and basic properties the signed-in user can already see. |
    | `Channel.ReadBasic.All` <br /> Read the names and descriptions of channels | List channels | Read channel names in teams the user can already access, so chat can find the right channel. |
    | `ChannelMessage.Read.All` <br /> Read user channel messages | Search channel messages | Read channel messages in teams the user can already open. Used to pull thread context into chat. |
    | `ChannelMessage.Send` <br /> Send channel messages | Post to a channel | Send a message as the user to a channel they already belong to. Users can set this action to **Needs approval** or **Block**. |
    | `Chat.Read` <br /> Read user chat messages | Search 1:1 and group chats | Read the signed-in user's chat messages for context in GC AI. |
    | `Chat.ReadWrite` <br /> Read and write user chat messages | Send chat messages | Write counterpart to `Chat.Read`. Required to send a chat as the user. |
    | `ChatMember.Read` <br /> Read the members of chats | See who is in a chat | Read chat membership so GC AI can identify participants. |
    | `ChatMember.ReadWrite` <br /> Add and remove members from chats | Update chat membership | Requested with the Teams connector. Add or update members in chats the user can already manage. Not used to create chats the user could not create in Teams. |
    | `TeamMember.Read.All` <br /> Read the members of teams | See team membership | Read members of teams the user can already access, so search and addressing work. |
    | `TeamMember.ReadWrite.All` <br /> Add and remove members from teams | Update team membership | Write counterpart for membership changes the user can already make in Teams. |
    | `User.Read.All` <br /> Read all users' full profiles | Look up colleagues | Delegated people lookup when addressing a chat or matching a name in search. Limited to directory data Microsoft already exposes to that user. |
    | `Directory.Read.All` <br /> Read directory data | Resolve directory objects for Teams | Microsoft Graph uses directory reads to resolve users, groups, and related objects when listing teams, chats, and members. Delegated: the signed-in user's existing directory visibility. |
    | `Group.ReadWrite.All` <br /> Read and write all groups | Teams as Microsoft 365 Groups | Teams are Microsoft 365 Groups. This scope supports team and channel operations the connector exposes, limited to groups the user can already manage. Org admins who want Read-only Teams can set the connector to **Read-only** in **Settings → Policies**. |
  </Accordion>

  <Accordion title="Microsoft OneNote">
    | Permission | GC AI feature | Why this access level |
    | - | - | - |
    | `Notes.Read.All` <br /> Read all OneNote notebooks that user can access | Search notebooks, sections, and pages | Read notebooks the signed-in user can already open, and pull page content into chat. |
    | `Notes.ReadWrite.All` <br /> Read and write all OneNote notebooks that user can access | Create notebooks, sections, and pages | Required when a user asks GC AI to capture a note. Read alone cannot create pages. |
  </Accordion>
</AccordionGroup>

## Security questions

### Which GC AI features use these permissions?

In product terms, the Microsoft 365 connectors support:

* **Microsoft Outlook:** search and read mail, drafts, send mail, calendar read/create/update, contact lookup
* **Microsoft OneDrive:** browse, search, and read files; upload or save files when the user asks
* **Microsoft SharePoint:** discover sites, search and retrieve documents; upload files, create Word documents, and edit Excel workbooks when the user asks
* **Microsoft Teams:** search chats and channels; send messages when the user asks
* **Microsoft OneNote:** search notebooks and pages; create or update notes when the user asks

Users connect each app separately. A user who only connects Microsoft Outlook does not get Teams or SharePoint tools until they connect those apps.

### Can you support Sites.Selected instead of Sites.Read.All?

Not as a drop-in replacement with current product behavior. `Sites.Selected` requires a tenant admin to pre-authorize specific SharePoint site IDs for the application. GC AI's SharePoint connector is built so each user can search and open sites and libraries they already have access to in Microsoft 365. Switching to `Sites.Selected` would mean every new site needs a separate admin grant, and would block open site discovery.

If your tenant has a fixed, small set of sites and wants least-privilege site allowlisting, that is a reasonable follow-up for GC AI. It is a scoped change and needs a clear site list from your team.

### Why is Sites.ReadWrite.All required?

The SharePoint connector includes user-initiated write features: upload a file to a library, create a Word document, and edit Excel content in SharePoint. `Sites.Read.All` alone cannot perform those writes. Access remains delegated to what the signed-in user can already do in SharePoint.

If you want SharePoint read-only, a GC AI org admin can set Microsoft SharePoint to **Read-only** under **Settings → Policies**. That disables write tools. Full write features stay off until policy is changed.

### Does GC AI make any changes to SharePoint content?

Only when the user asks for a write action: uploading a file, creating a Word document, or editing Excel in a SharePoint library. GC AI does not independently crawl or modify SharePoint content in the background. In Settings, write actions sit under the **Write & delete** tool group. That is the product label for write actions. GC AI does not expose a SharePoint delete-file action.

### Does GC AI write back, edit, update, or delete files or data in SharePoint sites?

**Write / create / update:** Yes, when the user requests it (upload, create Word doc, Excel edits), subject to that user's per-action settings in GC AI.

**Delete:** GC AI does not expose a SharePoint delete-file product action. We do not delete SharePoint files or sites as part of normal connector use.

### Is document content retained after processing, or fetched on demand?

Content is fetched from Microsoft on demand when the user asks for it in chat, or when the user chooses to import or sync files into GC AI. It is not mirrored as a standing full copy of the user's SharePoint or OneDrive.

For subprocessors and zero data retention, see [gc.ai/subprocessors](https://gc.ai/subprocessors) and [Zero data retention](/security/zero-data-retention).

### Can we grant only some of these permissions?

Yes, with tradeoffs. After admin consent, a Microsoft admin can revoke individual Graph permissions on the GC AI enterprise app in Entra. A GC AI org admin can set a connector to **Disabled**, **Read-only**, or **Full access** under **Settings → Policies**. Users can set each action to **Always allow**, **Needs approval**, or **Block** under **Tools**.

Tools that need a revoked scope become unavailable. For example, revoking Teams send scopes leaves Teams search in place and turns off posting.

## Related

* [Agent Connectors](/guides/organizations/agent-connectors)
* [Security overview](/security/overview)
* [Zero data retention](/security/zero-data-retention)
* [Subprocessor list](https://gc.ai/subprocessors)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.