Skip to main content

Overview

Connecting Microsoft 365 means approving the Velatir Connector app in your Microsoft Entra tenant. This page lists every permission that app asks for, what Velatir uses it for, and what happens if it is missing, so you can review the request before you accept it. Every permission is read-only. Velatir cannot change, send, or delete anything in your tenant.

Who Can Approve

The Velatir Connector app asks for Microsoft Graph application permissions. Microsoft lets only two roles approve those for a whole organisation:
  • Global Administrator
  • Privileged Role Administrator
Application Administrator and Cloud Application Administrator cannot approve application permissions for Microsoft Graph. If someone with one of those roles signs in, Microsoft asks for an administrator’s approval instead. On the Velatir side, the person who starts the connection needs the organisation Administrator role.

The App You Approve

Velatir Connector is a multi-tenant app that Velatir registers and maintains. It is not the app behind Sign in with Microsoft and Entra member sync. The two are approved separately, so:
  • Organisations that already use Entra sign-in do not get the connector’s permissions until an admin approves the connector.
  • Approving, revoking, or deleting the connector does not affect how anyone signs in to Velatir.

How Velatir Uses the Approval

An admin signs in

The first Microsoft screen is a sign-in that asks only for openid. It tells Velatir which directory the admin belongs to. Velatir connects that directory and refuses an approval for any other.

The admin approves for the organisation

Microsoft’s consent screen lists the permissions below. Accepting it grants them to Velatir Connector in your tenant only.

Velatir checks the approval

Before it saves anything, Velatir asks Microsoft for an access token for your tenant, checks that the token carries the permissions it needs, and makes one test call to Microsoft Graph. If any check fails, nothing is saved.

Velatir reads on its own schedule

From then on Velatir reads as the app, not as the admin who approved it. No one needs to stay signed in, and the connection keeps working when that admin leaves.
Velatir never sees a password, and you do not create a secret or certificate for Velatir. Velatir signs in to Microsoft with the app’s own credential, which Velatir manages. Microsoft then issues short-lived access tokens for your tenant, and Velatir holds them only in memory. For your organisation, Velatir stores only which tenant approved, when, and which permissions it granted.

The Permissions

Several of these permissions are broader than what Velatir reads with them. Microsoft does not offer narrower ones, so Velatir limits itself:
  • User.Read.All covers every user’s profile. Velatir looks up only people with a Copilot licence and people who appear in Copilot audit records.
  • Reports.Read.All covers every Microsoft 365 usage report. Velatir reads only the Copilot report.
  • AuditLogsQuery.Read.All covers the audit log of every Microsoft 365 service. Velatir queries only Copilot interaction records.
What Velatir collects says what Velatir brings in from conversations, audit records, and licences.

What Velatir Cannot Do

None of the permissions lets Velatir write. Velatir cannot:
  • Send mail, post messages, or act as a user.
  • Create, change, or delete users, groups, licences, or settings.
  • Read mailboxes, OneDrive or SharePoint files, Teams chats, or calendars.
A Copilot response can still quote content Copilot read for the user, such as a passage from a document or an email. That text reaches Velatir as part of the response, and your privacy settings decide whether it is kept.

If a Permission Is Missing

Velatir checks the approval with a fresh token every 15 minutes, so a change made in Entra shows on the card within that time. If a permission Velatir needs is missing, the connection shows Action needed with Permissions missing, followed by the names of the missing permissions. Velatir stops reading until it is fixed. Select Reconnect and accept every permission Microsoft lists. Some permissions only add to what Velatir brings in. Without AuditLogsQuery.Read.All, for example, the connection stays Connected, but there are no audit records and no activity from Copilot Chat users without a licence. Microsoft can take a few minutes to apply a new approval. If you see Permissions missing right after accepting, wait a few minutes and select Reconnect.

Review or Revoke the Approval in Entra

Open the app

In the Microsoft Entra admin center, open Enterprise applications and select Velatir Connector.

Review its permissions

Open Permissions. The Admin consent tab lists every permission your organisation granted, by the same names as on this page.

Revoke, if you want to

Revoke individual permissions there, or delete the app to remove all of Velatir’s access. Within 15 minutes the connection in Velatir shows Action needed. Everything Velatir already imported is kept.

Connect Microsoft 365

Before you start, and the connection steps.

What Velatir collects

What is read from Microsoft, what is kept, and what is left out.