Microsoft lists every Graph permission on GC AI’s app in one pass, not one list per connector. After you accept, the same Graph names appear in Entra under Enterprise applications → GC AI → Permissions → Admin consent.
Grant tenant admin consent (admins)
1
Start the connect flow
Open Settings → Integrations → Agent Connectors and select Connect on a Microsoft 365 app (Outlook, Teams, OneDrive, SharePoint, or OneNote).
2
Send or complete the approval
The connect dialog says Microsoft requires a one-time admin approval. Use Copy approval link and send it to your Microsoft 365 admin, or select Approve now if you have that role.
3
Accept Microsoft's consent screen
Complete Microsoft’s admin consent screen. Compare the Graph names on that screen to the tables below.
Connect your account
After admin consent is in place, each person connects their own account:- Open Settings → Integrations → Agent Connectors.
- Select Connect on the Microsoft 365 app you want.
- Complete Microsoft’s sign-in flow for your account.
What ”.All” means on delegated scopes
Scopes such asSites.Read.All and ChannelMessage.Read.All are delegated. GC AI can reach only the sites, files, chats, and teams the signed-in user can already open in Microsoft 365. .All means all of that user’s existing access, not application-only access to the whole tenant.
Permission justifications
These are the delegated Microsoft Graph permissions GC AI requests for Microsoft 365 connectors. The first column is the Graph name you see in Entra. The line under it is the label Microsoft shows on the consent screen.Microsoft Outlook
Microsoft Outlook
Microsoft OneDrive
Microsoft OneDrive
If your Entra Admin consent tab also lists
Files.Read and Files.ReadWrite, those are the original OneDrive file scopes. They cover the signed-in user’s own files. The OneDrive connector now requests Files.Read.All and Files.ReadWrite.All.Microsoft Teams
Microsoft Teams
Microsoft OneNote
Microsoft OneNote
Security questions
Which GC AI features use these permissions?
In product terms, the Microsoft 365 connectors support:- Microsoft Outlook: search and read mail, drafts, send mail, calendar read/create/update, contact lookup
- Microsoft OneDrive: browse, search, and read files; upload or save files when the user asks
- Microsoft SharePoint: discover sites, search and retrieve documents; upload files, create Word documents, and edit Excel workbooks when the user asks
- Microsoft Teams: search chats and channels; send messages when the user asks
- Microsoft OneNote: search notebooks and pages; create or update notes when the user asks
Can you support Sites.Selected instead of Sites.Read.All?
Not as a drop-in replacement with current product behavior.Sites.Selected requires a tenant admin to pre-authorize specific SharePoint site IDs for the application. GC AI’s SharePoint connector is built so each user can search and open sites and libraries they already have access to in Microsoft 365. Switching to Sites.Selected would mean every new site needs a separate admin grant, and would block open site discovery.
If your tenant has a fixed, small set of sites and wants least-privilege site allowlisting, that is a reasonable follow-up for GC AI. It is a scoped change and needs a clear site list from your team.
Why is Sites.ReadWrite.All required?
The SharePoint connector includes user-initiated write features: upload a file to a library, create a Word document, and edit Excel content in SharePoint.Sites.Read.All alone cannot perform those writes. Access remains delegated to what the signed-in user can already do in SharePoint.
If you want SharePoint read-only, a GC AI org admin can set Microsoft SharePoint to Read-only under Settings → Policies. That disables write tools. Full write features stay off until policy is changed.