Cloud Management Services for Microsoft 365

Refer to the table below for the apps that you can use for Cloud Management Services for Microsoft 365 and the requirements to consent to app permissions.

CategoryApp type in AOSApp setup methodFeature/ModuleApp name in Entra IDNew or updated?Consent
Service appCloud Management Services for Microsoft 365Modern modeAll objects managementAvePoint Cloud Management Service for Microsoft365No changesCreate or re-authorize an app profile in AOS > Management > App management.
Classic app
Microsoft 365 (All Permissions)Classic modeSharePoint Online
OneDrive
Microsoft Teams
Microsoft 365 Group
AvePoint Online Services Administration for Microsoft365No changesApp management > Classic mode > Consented for all services.
Classic app
Microsoft Entra IDClassic modeRequired by the Identity Manager module of the Cloud Management service.AvePoint Online Services Administration for Entra IDNo changesApp management > Classic mode > Consented for all services.
Classic app
Reporting for Microsoft 365Modern modeCollect Microsoft 365 dataAvePoint Reporting for Microsoft365No changesApp management > Modern mode > Consented for all services.

Permissions Required by Cloud Management Services for Microsoft 365

When you create a Cloud Management Services for Microsoft 365 app profile in AvePoint Online Services, the AvePoint Cloud Management Service for Microsoft365 app will be automatically set up in your Microsoft Entra ID.

The table below lists the permissions that should be accepted when you authorize AvePoint Cloud Management Service for Microsoft365 app.

APIPermissionTypePurposeIs newly required?
Microsoft GraphUser.ReadWrite.All
(Read and write all users' full profiles)
ApplicationRetrieve and update user properties.No
Microsoft GraphGroup.ReadWrite.All
(Read and write all groups)
ApplicationCreate and manage groups/teams.No
Microsoft GraphDirectory.Read.All
(Read directory data)
ApplicationRetrieve information from your organization’s Active Directory.No
Microsoft GraphMember.Read.Hidden
(Read all hidden memberships)
ApplicationRead the members of a group/team with hidden membership.No
Office 365 Exchange Onlinefull_access_as_app
(Use Exchange Web Services with full access to all mailboxes)
ApplicationRetrieve information of Exchange Online mailboxes and Microsoft 365 Group mailboxes.No
Office 365 Exchange OnlineExchange.ManageAsApp
(Manage Exchange as application)
ApplicationAllow the backup and restore of mailbox data.No
SharePoint/Office 365 SharePoint OnlineUser.ReadWrite.All
(Read and write all users’ full profiles)
ApplicationRetrieve and update user properties from user profiles.No
SharePoint/Office 365 SharePoint OnlineTermStore.ReadWrite.All
(Read and write managed metadata)
ApplicationRetrieve term store information.No
SharePoint/Office 365 SharePoint OnlineSites.FullControl.All
(Have full control of all site collections)
ApplicationRetrieve and manage SharePoint objects.No