- Joined
- Jan 14, 2013
- Messages
- 112
- Reaction score
- 44
The Microsoft 365 integration setup instructs to grant the Mail.Send application permission in the Azure Application, which is defined as "Allows the app to send mail as any user without a signed-in user."
From a least-privilege security perspective, this seems overly broad, and I am unable to identify any element of the integration for SSO or other features which engage in sending e-mail as a user. Also, this is the only permission requested which is not just a "Read" permission.
Can you help me understand the need for this permission to be assigned?
From a least-privilege security perspective, this seems overly broad, and I am unable to identify any element of the integration for SSO or other features which engage in sending e-mail as a user. Also, this is the only permission requested which is not just a "Read" permission.
Can you help me understand the need for this permission to be assigned?
