> For the complete documentation index, see [llms.txt](https://docs.easydirectory.easyplatform.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.easydirectory.easyplatform.app/administration/permissions.md).

# Permissions

Easy Directory requires two separate app registrations within your tenant to ensure functionality and security:

1. **Easy Directory**:\
   This primary app handles the core functionalities, enabling the display of your contacts directly within Microsoft Teams.
2. **Easy Directory Configuration**:\
   To enhance security, a second app registration with elevated permissions is used to change the users configuration
3. **Easy Platform Configuration Center**:\
   To enhance security, a third app registration with elevated permissions is used for configuration tasks. This app allows:
   * Access to contacts stored in shared mailboxes.
   * The provision of a dedicated portal for managing contacts and views.

Access to the **Easy Platform Configuration Portal** is restricted to users assigned the **Teams Administrator** role, ensuring that only authorized personnel can manage the platform’s configuration and permissions.

This two-app approach guarantees both robust functionality and a secure management environment for Easy Directory.

## Easy Directory

<table><thead><tr><th width="199">Permission</th><th width="377">Description</th><th>Type<select><option value="HQUa6fTcNxmV" label="Application" color="blue"></option><option value="SzrYr0CHyycr" label="Delegated" color="blue"></option></select></th></tr></thead><tbody><tr><td>Contacts.ReadWrite</td><td>Create, update, read, and delete the user's own contacts.</td><td><span data-option="SzrYr0CHyycr">Delegated</span></td></tr><tr><td>Contacts.ReadWrite.Shared</td><td>Manage contacts in shared mailboxes the user is permitted to access.</td><td><span data-option="SzrYr0CHyycr">Delegated</span></td></tr><tr><td>MailboxSettings.ReadWrite</td><td>Provides read/write mailbox settings access, including master categories.</td><td><span data-option="SzrYr0CHyycr">Delegated</span></td></tr><tr><td>Presence.Read.All</td><td>Read presence info of all users on behalf of the signed-in user.</td><td><span data-option="SzrYr0CHyycr">Delegated</span></td></tr><tr><td>User.Read.All</td><td>Read full profiles of all users.</td><td><span data-option="SzrYr0CHyycr">Delegated</span></td></tr><tr><td>User.Read</td><td>Basic signed-in user profile.</td><td><span data-option="SzrYr0CHyycr">Delegated</span></td></tr><tr><td>openid</td><td>Request an ID token (OIDC identity scope).</td><td><span data-option="SzrYr0CHyycr">Delegated</span></td></tr><tr><td>profile</td><td>Access standard profile claims (name, email, etc.).</td><td><span data-option="SzrYr0CHyycr">Delegated</span></td></tr><tr><td>offline_access</td><td>Allows issuing refresh tokens.</td><td><span data-option="SzrYr0CHyycr">Delegated</span></td></tr><tr><td>Contacts.Read</td><td>Read all contacts in all mailboxes without a user.</td><td><span data-option="HQUa6fTcNxmV">Application</span></td></tr><tr><td>User.Read.All</td><td>Read user profiles without a signed-in user.</td><td><span data-option="HQUa6fTcNxmV">Application</span></td></tr></tbody></table>

## Easy Directory Admin (Configuration)

<table><thead><tr><th width="176">Permission</th><th width="394">Description</th><th>Type<select><option value="olQHTOz5mRcj" label="Delegated" color="blue"></option></select></th></tr></thead><tbody><tr><td>Presence.Read.All</td><td>Read presence information of all users on behalf of the signed-in user.</td><td><span data-option="olQHTOz5mRcj">Delegated</span></td></tr><tr><td>User.Read</td><td>Basic signed-in user profile.</td><td><span data-option="olQHTOz5mRcj">Delegated</span></td></tr><tr><td>User.ReadBasic.All</td><td>Read all users' full profiles.</td><td><span data-option="olQHTOz5mRcj">Delegated</span></td></tr><tr><td>offline_access</td><td>Allows issuing refresh tokens.</td><td><span data-option="olQHTOz5mRcj">Delegated</span></td></tr><tr><td>openid</td><td>OIDC scope for ID token.</td><td><span data-option="olQHTOz5mRcj">Delegated</span></td></tr><tr><td>profile</td><td>Standard profile claims (name, email, etc.).</td><td><span data-option="olQHTOz5mRcj">Delegated</span></td></tr></tbody></table>

## Easy Platform Configuration Center Admin

<table><thead><tr><th width="180">Permission</th><th width="402">Description</th><th>Type<select><option value="I3fXQlMw2hBp" label="Delegated" color="blue"></option></select></th></tr></thead><tbody><tr><td>Application.Read.All</td><td>Read applications and service principals on behalf of the signed-in user.</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>Presence.Read.All</td><td>Read presence information of all users in your organization.</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>email</td><td>View users' email address (OIDC email claim).</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>offline_access</td><td>Maintain access to data you have given it access to (issue refresh tokens).</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>openid</td><td>Sign users in (request ID token via OpenID Connect).</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>profile</td><td>View basic profile information.</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>User.Read</td><td>Sign in and read the signed-in user's profile.</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>User.Read.All</td><td>Read full profiles of all users in the organization.</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr></tbody></table>

**Optional features**

<table><thead><tr><th width="180.333251953125">Permission</th><th width="402.3333740234375">Description</th><th>Type<select><option value="SCahpwXbhYhz" label="Delegated" color="blue"></option></select></th></tr></thead><tbody><tr><td>CrossTenantInformation.ReadBasic.All</td><td><p><strong>Reseller tenant name resolution</strong></p><p>Show customer tenant display names (instead of only tenant IDs) in reseller subscriptions.</p></td><td><span data-option="SCahpwXbhYhz">Delegated</span></td></tr></tbody></table>
