---
title: "User Roles and Application Permissions"
slug: "user-roles-and-application-permissions-for-o365"
updated: 2025-04-10T03:25:10Z
published: 2025-04-10T03:25:10Z
canonical: "kb.expedient.com/user-roles-and-application-permissions-for-o365"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://kb.expedient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# User Roles and Application Permissions

### Introduction

To register your Microsoft 365 domain and protect the Microsoft 365 data using Cohesity, please ensure the following prerequisites are met:

1. A Microsoft 365 user account with the requisite roles
2. Custom application with the requisite permissions

*Cohesity requires a Microsoft domain user account to discover and protect Office 365 Exchange Online-related data. The user account does not need to be licensed with a valid Microsoft 365 license.*

*Cohesity uses the Microsoft Graph, Office 365 Exchange Online, SharePoint, and EWS APIs for secure authentication, object discovery, backup, and recovery in Microsoft 365. Cohesity uses a custom app created and registered on the Azure portal to use said APIs.*

<editor360-custom-block data-preprocessing="true" data-sanitizationtags="em,span"><section class="warningBox"><div class="title"><em>Disclaimer: the configuration of specific user roles and application permissions may differ per Microsoft 365 environment. If you're having difficulties setting up the <span style="color:rgb(127, 100, 22);font-family:Nunito, sans-serif;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:600;letter-spacing:0.48px;orphans:2;text-align:left;text-indent:0px;text-transform:none;white-space:normal;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;background-color:rgb(253, 242, 206);text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;float:none;--darkreader-inline-color:#ffff9a;--darkreader-inline-bgcolor:#4a3a03;display:inline !important;" data-darkreader-inline-color="" data-darkreader-inline-bgcolor=""></span>user roles and application permissions<span style="color:rgb(127, 100, 22);font-family:Nunito, sans-serif;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:600;letter-spacing:0.48px;orphans:2;text-align:left;text-indent:0px;text-transform:none;white-space:normal;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;background-color:rgb(253, 242, 206);text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;float:none;--darkreader-inline-color:#ffff9a;--darkreader-inline-bgcolor:#4a3a03;display:inline !important;" data-darkreader-inline-color="" data-darkreader-inline-bgcolor=""></span> that Cohesity requires, please contact Microsoft</em><em> for assistance</em><em>.</em></div></section></editor360-custom-block>

### User Roles

| User Roles | Why It's Required? |
| --- | --- |
| View-Only Configuration | Enables administrators to view all the non-recipient Exchange configuration settings in an organization. |
| View-Only Recipients | Enables administrators to view the configuration of recipients, such as mailboxes, mail users, mail contacts, distribution groups, and dynamic distribution groups. |
| MailboxSearch | Enables administrators to search the content of one or more mailboxes in an organization. |
| MailRecipients | Enables administrators to manage existing mailboxes, mail users, mail contacts, distribution groups, and dynamic distribution groups in an organization. |

*You can combine the View-Only Configuration with roles associated with the View-Only Recipients role to create a role group that can view every object in an organization.*

### Application Permissions

| App Permissions | Permission Type | Mailbox | OneDrive | SharePoint | Group | Teams |
| --- | --- | --- | --- | --- | --- | --- |
| AllSites.FullControl | Delegated | **YES** | **YES** | **YES** | **YES** | **YES** |
| AllSites.Manage | Delegated | **YES** | **YES** | **YES** | **YES** | **YES** |
| AllSites.Read | Delegated | **YES** | **YES** | **YES** | **YES** | **YES** |
| Channel.Create | Application | N/A | N/A | N/A | N/A | **YES** |
| Channel.ReadBasic.All | Application | N/A | N/A | N/A | N/A | **YES** |
| ChannelMember.ReadWrite.All | Application | N/A | N/A | N/A | N/A | **YES** |
| Directory.ReadWrite.All | Application | **YES** | **YES** | **YES** | **YES** | **YES** |
| Files.ReadWrite.All | Application | N/A | **YES** | **YES** | **YES** | **YES** |
| Group.ReadWrite.All | Application | N/A | **YES** | **YES** | **YES** | **YES** |
| Group.Read.All | Application | N/A | **YES** | **YES** | **YES** | **YES** |
| Group.Create | Application | N/A | N/A | N/A | **YES** | **YES** |
| MailboxSettings.Read | Application | **YES** | N/A | N/A | N/A | N/A |
| MyFiles.Read | Delegated | **YES** | **YES** | **YES** | **YES** | **YES** |
| MyFiles.Write | Delegated | **YES** | **YES** | **YES** | **YES** | **YES** |
| Reports.Read.All | Application | **YES** | **YES** | **YES** | **YES** | **YES** |
| Sites.FullControl.All | Application | N/A | N/A | **YES** | **YES** | **YES** |
| Sites.Manage.All | Application | **YES** | **YES** | **YES** | **YES** | **YES** |
| Sites.Read.All | Application | N/A | N/A | N/A | **YES** | **YES** |
| Sites.ReadWrite.All | Application | **YES** | **YES** | **YES** | **YES** | **YES** |
| Sites.Search.All | Delegated | **YES** | **YES** | **YES** | **YES** | **YES** |
| TermStore.ReadWrite.All | Application | **YES** | **YES** | **YES** | **YES** | **YES** |
| TermStore.ReadWrite.All | Delegated | **YES** | **YES** | **YES** | **YES** | **YES** |
| User.Read.All | Application | **YES** | **YES** | **YES** | **YES** | **YES** |
| User.ReadWrite.All | Application | N/A | N/A | **YES** | **YES** | **YES** |
| User.ReadWrite.All | Delegated | **YES** | **YES** | **YES** | **YES** | **YES** |

### OAuth 2.0 Authentication for EWS API

Cohesity supports OAuth 2.0 authentication for more secure communication with O365. To enable OAuth 2.0 authentication for Microsoft Exchange Online or the Microsoft Graph API permission **User.Read.All**, you need to add Office 365 Exchange Online, **full_access_as_app** permission to the custom app.

### Add-in Permissions in SharePoint

| Scope URI | Required Rights |
| --- | --- |
| http://sharepoint/content/tenant | FullControl |
| http://sharepoint/content/sitecollection | FullControl |
| http://sharepoint/content/sitecollection/web | FullControl |
| http://sharepoint/content/sitecollection/web/list | FullControl |
| http://sharepoint/taxonomy | Read,Write |

### **Tenant Permissions**

For recovering the SharePoint Online site to the Microsoft 365 tenant or an alternate Microsoft 365 tenant, please ensure that you configure the following Custom Scripts permissions on the tenant:

1. Allow users to run custom scripts on personal sites 2. Allow users to run custom scripts on self-service created sites
