- Joined
- Jan 24, 2018
- Messages
- 4
- Reaction score
- 1
Hello everyone,
I am writing this post to request a critical improvement in how 3CX manages its integration with Microsoft 365 and Teams (Direct Routing).
While this makes life easier for SMEs, it is a blocker for clients of a certain size. As discussed in other threads (referencing the case of javier.fletcher), a client with a global presence cannot allow a PBX, which will only be used in a local branch, to have write permissions over their entire global Tenant.
Thank you.
I am writing this post to request a critical improvement in how 3CX manages its integration with Microsoft 365 and Teams (Direct Routing).
The Current Problem
Currently, the 3CX integration wizard requires Global Administrator credentials and requests excessive permissions over the Microsoft Tenant (Read/Write across the entire directory, Calendars, SharePoint, etc.) to complete the configuration.While this makes life easier for SMEs, it is a blocker for clients of a certain size. As discussed in other threads (referencing the case of javier.fletcher), a client with a global presence cannot allow a PBX, which will only be used in a local branch, to have write permissions over their entire global Tenant.
The Security Blockade
Client CISO/Security departments reject the integration for two reasons:- Violation of the "Least Privilege" Principle: It cannot be justified to give access to SharePoint or Calendars if we only need Voice/Teams Direct Routing.
- Exposure Risk: They do not want to sync/expose their entire Azure AD (Entra ID) user structure when only a fraction will use 3CX.
The Proposed Solution
We need an "Advanced Configuration" mode that allows for:- Granular Permission Selection: The ability to choose which permissions to grant. If I only want telephony, I should be able to disable contact/calendar/SharePoint synchronization.
- Manual Azure App Registration: Instead of forcing the use of the automated Wizard (which requires Global Admin), allow us to manually enter the Application ID, Directory ID, and Client Secret of an App that we have created ourselves in Azure with the strictly necessary permissions (Scoped Permissions).
- Pre-Synchronization Filtering: The ability to limit which O365 security groups 3CX "sees" before the initial synchronization occurs.
Thank you.
Upvote
5