Skip to main content
Microsoft 365 covers Outlook, Teams, OneDrive, SharePoint, and OneNote. These apps share one Microsoft Entra app. A tenant admin grants consent once. After that, each person connects their own Microsoft account in GC AI. GC AI then acts with that person’s existing Microsoft access. It does not receive tenant-wide application access that bypasses the user’s permissions.
Microsoft lists every Graph permission on GC AI’s app in one pass, not one list per connector. After you accept, the same Graph names appear in Entra under Enterprise applications → GC AI → Permissions → Admin consent.
1

Start the connect flow

Open Settings → Integrations → Agent Connectors and select Connect on a Microsoft 365 app (Outlook, Teams, OneDrive, SharePoint, or OneNote).
2

Send or complete the approval

The connect dialog says Microsoft requires a one-time admin approval. Use Copy approval link and send it to your Microsoft 365 admin, or select Approve now if you have that role.
3

Accept Microsoft's consent screen

Complete Microsoft’s admin consent screen. Compare the Graph names on that screen to the tables below.
Org admins then set each connector to Disabled, Read-only, or Full access under Settings → Policies. Under a connected app, expand Tools to set each action to Always allow, Needs approval, or Block. Tools are grouped as Read (defaulting to Always allow) and Write & delete (defaulting to Needs approval). See Agent Connectors.

Connect your account

After admin consent is in place, each person connects their own account:
  1. Open Settings → Integrations → Agent Connectors.
  2. Select Connect on the Microsoft 365 app you want.
  3. Complete Microsoft’s sign-in flow for your account.
Admins cannot connect Outlook, Teams, OneDrive, SharePoint, or OneNote on your behalf. You authorize your own account. Most organizations see Microsoft SharePoint in Settings. If you do not, contact your GC AI account team. Admin consent is for the shared Microsoft app, so SharePoint Graph permissions can still appear on Microsoft’s screen even when the SharePoint tile is hidden.

What ”.All” means on delegated scopes

Scopes such as Sites.Read.All and ChannelMessage.Read.All are delegated. GC AI can reach only the sites, files, chats, and teams the signed-in user can already open in Microsoft 365. .All means all of that user’s existing access, not application-only access to the whole tenant.

Permission justifications

These are the delegated Microsoft Graph permissions GC AI requests for Microsoft 365 connectors. The first column is the Graph name you see in Entra. The line under it is the label Microsoft shows on the consent screen.
If your Entra Admin consent tab also lists Files.Read and Files.ReadWrite, those are the original OneDrive file scopes. They cover the signed-in user’s own files. The OneDrive connector now requests Files.Read.All and Files.ReadWrite.All.

Security questions

Which GC AI features use these permissions?

In product terms, the Microsoft 365 connectors support:
  • Microsoft Outlook: search and read mail, drafts, send mail, calendar read/create/update, contact lookup
  • Microsoft OneDrive: browse, search, and read files; upload or save files when the user asks
  • Microsoft SharePoint: discover sites, search and retrieve documents; upload files, create Word documents, and edit Excel workbooks when the user asks
  • Microsoft Teams: search chats and channels; send messages when the user asks
  • Microsoft OneNote: search notebooks and pages; create or update notes when the user asks
Users connect each app separately. A user who only connects Microsoft Outlook does not get Teams or SharePoint tools until they connect those apps.

Can you support Sites.Selected instead of Sites.Read.All?

Not as a drop-in replacement with current product behavior. Sites.Selected requires a tenant admin to pre-authorize specific SharePoint site IDs for the application. GC AI’s SharePoint connector is built so each user can search and open sites and libraries they already have access to in Microsoft 365. Switching to Sites.Selected would mean every new site needs a separate admin grant, and would block open site discovery. If your tenant has a fixed, small set of sites and wants least-privilege site allowlisting, that is a reasonable follow-up for GC AI. It is a scoped change and needs a clear site list from your team.

Why is Sites.ReadWrite.All required?

The SharePoint connector includes user-initiated write features: upload a file to a library, create a Word document, and edit Excel content in SharePoint. Sites.Read.All alone cannot perform those writes. Access remains delegated to what the signed-in user can already do in SharePoint. If you want SharePoint read-only, a GC AI org admin can set Microsoft SharePoint to Read-only under Settings → Policies. That disables write tools. Full write features stay off until policy is changed.

Does GC AI make any changes to SharePoint content?

Only when the user asks for a write action: uploading a file, creating a Word document, or editing Excel in a SharePoint library. GC AI does not independently crawl or modify SharePoint content in the background. In Settings, write actions sit under the Write & delete tool group. That is the product label for write actions. GC AI does not expose a SharePoint delete-file action.

Does GC AI write back, edit, update, or delete files or data in SharePoint sites?

Write / create / update: Yes, when the user requests it (upload, create Word doc, Excel edits), subject to that user’s per-action settings in GC AI. Delete: GC AI does not expose a SharePoint delete-file product action. We do not delete SharePoint files or sites as part of normal connector use.

Is document content retained after processing, or fetched on demand?

Content is fetched from Microsoft on demand when the user asks for it in chat, or when the user chooses to import or sync files into GC AI. It is not mirrored as a standing full copy of the user’s SharePoint or OneDrive. For subprocessors and zero data retention, see gc.ai/subprocessors and Zero data retention.

Can we grant only some of these permissions?

Yes, with tradeoffs. After admin consent, a Microsoft admin can revoke individual Graph permissions on the GC AI enterprise app in Entra. A GC AI org admin can set a connector to Disabled, Read-only, or Full access under Settings → Policies. Users can set each action to Always allow, Needs approval, or Block under Tools. Tools that need a revoked scope become unavailable. For example, revoking Teams send scopes leaves Teams search in place and turns off posting.
Last modified on September 5, 2026