Home > Microsoft > Configure App Profiles or Service Account Profiles > Configure App Profiles for Default Service Apps > Cloud Governance
Export to PDFInstructions….
Refer to the following sections to see the API permissions that should be accepted when you consent to the corresponding apps.
When you create a Cloud Governance for Microsoft 365 app profile in AvePoint Online Services, the AvePoint Cloud Governance forMicrosoft365 app will be automatically set up in your Microsoft Entra ID.
The table below lists the permissions that should be accepted when you authorize the AvePoint Cloud Governance for Microsoft365 app.
| API | Permission | Type | Purpose |
|---|---|---|---|
| Microsoft Graph | AuditLog.Read.All (Read all audit log data) | Application | Retrieve the user who invited the guest user to the tenant. |
| Microsoft Graph | Channel.Create (Create channels) | Application | Create private channels. |
| Microsoft Graph | Channel.Delete.All (Delete channels) | Application | Delete private channels. |
| Microsoft Graph | ChannelMember.ReadWrite.All (Add and remove members from all channels) | Application | Add members to private channels. |
| Microsoft Graph | ChannelMessage.Read.All(Read all channel messages) | Application | Retrieve Microsoft Teams channel conversations for team inactivity threshold calculation. |
| Microsoft Graph | ChannelSettings.ReadWrite.All (Read and write the names, descriptions, and settings of all channels) | Application | Update private channel properties. |
| Microsoft Graph | Community.ReadWrite.All(Read and write all Viva Engage communities) | Application | Create a new community in Viva Engage. |
| Microsoft Graph | Directory.Read.All(Read directory data) | Application | Retrieve information from your organization’s Active Directory. |
| Microsoft Graph | Files.Read.All(Read files in all site collections) | Application | Retrieve the URLs of the group team sites. |
| Microsoft Graph | Group.ReadWrite.All (Read and write all groups) | Application | Create and manage groups/teams. |
| Microsoft Graph | InformationProtectionPolicy.Read.All(Read all published labels and label policies for an organization) | Application | Manage sensitivity labels. |
| Microsoft Graph | Mail.Send(Send mail as any user) | Application | Use a Microsoft 365 account as the email sender to send notification emails. |
| Microsoft Graph | Member.Read.Hidden (Read all hidden memberships) | Application | Read the members of a group/team with hidden membership to copy members. |
| Microsoft Graph | Policy.Read.All(Read your organization's policies) | Application | Retrieve your organization’s policies. |
| Microsoft Graph | Reports.Read.All (Read all usage reports) | Application | Get user activities to filter active workspaces. |
| Microsoft Graph | Sites.FullControl.All(Have full control of all site collections) | Application | Manage content types. |
| Microsoft Graph | Sites.Read.All (Read items in all site collections) | Application | Retrieve the latest site collection URLs. |
| Microsoft Graph | Team.Create (Create teams) | Application | Create teams. |
| Microsoft Graph | TeamMember.ReadWrite.All(Add and remove members from all teams) | Application | Add or remove members from teams. |
| Microsoft Graph | TeamSettings.ReadWrite.All (Read and change all teams' settings) | Application | Retrieve and update team settings. |
| Microsoft Graph | User.Invite.All(Invite guest users to the organization) | Application | Invite guest users to groups/teams. |
| Microsoft Graph | User.ReadWrite.All (Read and write all users' full profiles) | Application | Retrieve and update user properties. |
| Microsoft Graph | User.Read(Sign in and read user profile) | Delegated | Search for users and retrieve user information. |
| Office 365 Management APIs | ActivityFeed.Read(Read activity data for your organization) | Application | Retrieve activity data in your organization. |
| SharePoint/Office 365 SharePoint Online | Sites.FullControl.All | Application | Retrieve and manage SharePoint objects. |
| SharePoint/Office 365 SharePoint Online | TermStore.ReadWrite.All(Read and write managed metadata) | Application | Retrieve term store information. |
| SharePoint/Office 365 SharePoint Online | User.Read.All(Read user profiles) | Application | Retrieve user properties from user profiles. |
| Microsoft Information Protection Sync Services | UnifiedPolicy.Tenant.Read(Read all unified policies of the tenant) | Application | Retrieve sensitivity labels in your organization.*Note: This API is used when sensitivity labels cannot be retrieved by the Microsoft Graph API. |
When you create a Cloud Governance for Exchange app profile in AvePoint Online Services, the AvePoint Cloud Governance Exchange App will be automatically set up in your Microsoft Entra ID.
The table below lists the permissions that should be accepted when you authorize the AvePoint Cloud Governance Exchange App.
| API | Permission | Type | Purpose |
|---|---|---|---|
| Microsoft Graph | User.Read(Sign in and read user profile) | Delegated | Search for users and retrieve user information. |
| Office 365 Exchange Online | full_access_as_app(Use Exchange Web Services with full access to all mailboxes) | Application | Create Microsoft 365 Groups/teams and update their properties. |
| Office 365 Exchange Online | Exchange.ManageAsApp(Manage Exchange as application) | Application | Provision and manage shared mailboxes, distribution lists, and mail-enabled security groups. Update Microsoft 365 Group properties. |
When you create a Cloud Governance for Power Platform app profile in AvePoint Online Services, the AvePoint Cloud Governance forPower Platform app will be automatically set up in your Microsoft Entra ID.
The table below lists the permissions that should be accepted when you authorize the AvePoint Cloud Governance for Power Platform app.
| API | Permission | Type | Purpose |
|---|---|---|---|
| Dynamics CRM | user_impersonation(Access Common Data Service as organization users) | Delegated | Manage Power Apps and Power Platform environments. |
| Microsoft Graph | Directory.Read.All(Read directory data) | Application | Retrieve information from your organization’s Active Directory. |
| Power BI Service | Tenant.Read.All(View all content in tenant) | Delegated | Retrieve information of Power BI workspace. |
| Power BI Service | Tenant.ReadWrite.All(Read and write all content in tenant) | Delegated | Update Power BI workspace roles. |
| Power BI Service | Workspace.ReadWrite.All(Read and write all workspaces) | Delegated | Delete Power BI workspaces. |
| PowerApps Service | User(Access the PowerApps Service API) | Delegated | Retrieve information of Power Apps. |
| PowerPages Service | PowerPages.Websites.Read(Read Power Pages websites) | Delegated | Manage Power Pages sites. |
| PowerPages Service | PowerPages.Website.Write(Write Power Pages websites) | Delegated | Manage Power Pages sites. |
When you create an app profile for Cloud Governance delegated app in AvePoint Online Services, the AvePoint Cloud Governance Delegated App will be automatically set up in your Microsoft Entra ID.
The table below lists the permissions that should be accepted when you authorize the AvePoint Cloud Governance Delegated App.
| API | Permission | Type | Purpose |
|---|---|---|---|
| Microsoft Graph | Group.ReadWrite.All(Read and write all groups) | Delegated | Retrieve and update Microsoft 365 Group’s information. |