Document Management System Online

Refer to the table below for the apps that you can use for Document Management System Online and the requirements to consent to app permissions.

CategoryApp type in AOSApp setup methodFeature/ModuleApp name in Entra IDNew or updated?Consent
Service appDMS OnlineModern modeAllAvePoint Document Management System OnlineNo changesCreate or re-authorize an app profile in AOS > Management > App management.

Permissions Required by Document Management System Online

When you create the DMS Online app profile in AvePoint Online Services, the AvePoint Document Management System Online app will be automatically set up in your Microsoft Entra ID.

The table below lists the permissions that should be accepted when you authorize AvePoint Document Management System Online app.

APIPermissionTypePurposeIs newly required?
Microsoft GraphAppCatalog.ReadWrite.All
(Read and write to all app catalogs)
DelegatedDeploy and publish Teams apps.No
Microsoft GraphDirectory.Read.All
(Read directory data)
ApplicationRetrieve Microsoft 365 users.No
Microsoft GraphGroup.ReadWrite.All
(Read and write all groups)
ApplicationRetrieve and add Microsoft 365 groups and group members.No
Microsoft GraphSites.FullControl.All
(Have full control of all site collections)
ApplicationRetrieve settings and permissions of SharePoint Online site collections.No
Microsoft GraphTeamMember.ReadWrite.All
(Add and remove members from all teams)
ApplicationRetrieve and manage Team members.No
Microsoft GraphChannelMember.ReadWrite.All
(Add and remove members from all channels)
ApplicationRetrieve and manage private channel members.No
Microsoft GraphTeamMember.ReadWrite.All
(Add and remove members from all teams)
DelegatedRetrieve and manage Team members.No
Microsoft GraphChannelMember.ReadWrite.All
(Add and remove members from all channels)
DelegatedRetrieve and manage private channel members.No
Microsoft GraphSites.FullControl.All
(Have full control of all site collections)
DelegatedRetrieve settings and permissions of SharePoint Online site collections. No
Microsoft GraphDirectory.Read.All
(Read directory data)
DelegatedRetrieve Microsoft 365 users.No
Microsoft GraphSites.Read.All
(Read items in all site collections)
DelegatedRetrieve site and library objects.No
Microsoft GraphFiles.ReadWrite.All
(Have full access to all files the user can access)
DelegatedRetrieve files that the user can access.No
Microsoft GraphMail.ReadWrite
(Read and write access to user mail)
DelegatedRetrieve user mail and email attachments.No
Microsoft GraphUser.Read
(Sign in and read user profile)
DelegatedSign in and read the user profile.No
SharePointSites.FullControl.All
(Have full control of all site collections)
ApplicationRetrieve settings and permissions of SharePoint Online site collections.No
SharePointTermStore.ReadWrite.All
(Read and write managed metadata)
ApplicationRetrieve and create managed metadata service.No
SharePointAllSites.FullControl
(Have full control of all site collections)
DelegatedRetrieve settings and permissions of SharePoint Online site collections. No
SharePointTermStore.ReadWrite.All
(Read and write managed metadata)
DelegatedRetrieve and create managed metadata service.No
SharePointSites.Search.All
(Run search queries as a user)
DelegatedFilter site collections that the user can access and allow the user to search objects in the site collections.No
SharePointUser.Read.All
(Read user profiles)
DelegatedRetrieve user profiles.No