Understanding permissions with Microsoft 365 enterprise apps

This article explains how Microsoft 365 enterprise apps work with Azure AD and what permissions they need. It walks through a generic app authorization as a Global Administrator and covers common security misconceptions. It then explains in more technical depth how a service account gets authorized and connected to Robin.

Read it if you want to know: "How do we let people sign in to Robin with Microsoft 365 without letting everyone authenticate with any app on the internet?"

Service Principal and Application objects

When you authorize the Robin app for the first time, it registers a Service Principal object in your Azure directory. This is your "install" of the Robin app, and you manage it directly. Robin maintains the Application object itself, so Robin can develop and maintain the app for all customers in one place.

Think of the Service Principal as an installed version of software, and the Application as the most recent version. If the Application changes (for example, it adds or removes a permission for features), you can authorize the most recent version again to update the Service Principal. This is very rare, and Robin does not need it to run.

This diagram from Microsoft shows the workflow:

o365-service-principal-flowchart.png

Add new applications in Microsoft 365

Microsoft sets this requirement for Global Administrators and applications in Azure AD:

Only global administrators can:

  • Add apps from the Azure AD app gallery (pre-integrated 3rd Party Apps)
  • Publish an app using the Azure AD Application Proxy

The first time you sign in to Robin's app, you must be a Global administrator, unless your tenant lets all users register new applications. Robin does not recommend this.

During sign up/in users are asked to give permission to the app to access their profile and other permissions. The first person to give consent causes a service principal representing the app to be added to the directory.

After you add the app to your directory, you no longer need the Global Administrator role to manage its settings.

User consent settings

When you enable "Users can consent to apps accessing company data on their behalf", regular users assigned to the app can sign in to existing service principals. It does not grant users the right to create new service principals (other apps you have not approved). The "Users can add gallery apps to their Access Panel" option controls new apps, and it can stay disabled.

User_concent_O365.png

In other words, the first option lets your users authorize only pre-approved apps. The second option lets them authorize any app they choose.

References

Articles in this section

Was this article helpful?
7 out of 17 found this helpful
Share