Overview
Connecting Microsoft 365 means approving the Velatir Connector app in your Microsoft Entra tenant. This page lists every permission that app asks for, what Velatir uses it for, and what happens if it is missing, so you can review the request before you accept it. Every permission is read-only. Velatir cannot change, send, or delete anything in your tenant.Who Can Approve
The Velatir Connector app asks for Microsoft Graph application permissions. Microsoft lets only two roles approve those for a whole organisation:- Global Administrator
- Privileged Role Administrator
The App You Approve
Velatir Connector is a multi-tenant app that Velatir registers and maintains. It is not the app behind Sign in with Microsoft and Entra member sync. The two are approved separately, so:- Organisations that already use Entra sign-in do not get the connector’s permissions until an admin approves the connector.
- Approving, revoking, or deleting the connector does not affect how anyone signs in to Velatir.
How Velatir Uses the Approval
An admin signs in
The first Microsoft screen is a sign-in that asks only for
openid. It tells Velatir which directory the admin belongs to. Velatir connects that directory and refuses an approval for any other.The admin approves for the organisation
Microsoft’s consent screen lists the permissions below. Accepting it grants them to Velatir Connector in your tenant only.
Velatir checks the approval
Before it saves anything, Velatir asks Microsoft for an access token for your tenant, checks that the token carries the permissions it needs, and makes one test call to Microsoft Graph. If any check fails, nothing is saved.
Velatir reads on its own schedule
From then on Velatir reads as the app, not as the admin who approved it. No one needs to stay signed in, and the connection keeps working when that admin leaves.
The Permissions
Several of these permissions are broader than what Velatir reads with them. Microsoft does not offer narrower ones, so Velatir limits itself:
User.Read.Allcovers every user’s profile. Velatir looks up only people with a Copilot licence and people who appear in Copilot audit records.Reports.Read.Allcovers every Microsoft 365 usage report. Velatir reads only the Copilot report.AuditLogsQuery.Read.Allcovers the audit log of every Microsoft 365 service. Velatir queries only Copilot interaction records.
What Velatir Cannot Do
None of the permissions lets Velatir write. Velatir cannot:- Send mail, post messages, or act as a user.
- Create, change, or delete users, groups, licences, or settings.
- Read mailboxes, OneDrive or SharePoint files, Teams chats, or calendars.
If a Permission Is Missing
Velatir checks the approval with a fresh token every 15 minutes, so a change made in Entra shows on the card within that time. If a permission Velatir needs is missing, the connection shows Action needed with Permissions missing, followed by the names of the missing permissions. Velatir stops reading until it is fixed. Select Reconnect and accept every permission Microsoft lists. Some permissions only add to what Velatir brings in. WithoutAuditLogsQuery.Read.All, for example, the connection stays Connected, but there are no audit records and no activity from Copilot Chat users without a licence.
Microsoft can take a few minutes to apply a new approval. If you see Permissions missing right after accepting, wait a few minutes and select Reconnect.
Review or Revoke the Approval in Entra
Open the app
In the Microsoft Entra admin center, open Enterprise applications and select Velatir Connector.
Review its permissions
Open Permissions. The Admin consent tab lists every permission your organisation granted, by the same names as on this page.
Revoke, if you want to
Revoke individual permissions there, or delete the app to remove all of Velatir’s access. Within 15 minutes the connection in Velatir shows Action needed. Everything Velatir already imported is kept.
Connect Microsoft 365
Before you start, and the connection steps.
What Velatir collects
What is read from Microsoft, what is kept, and what is left out.