Hi there

What are the differences between using a User Account or Application Account for an M365 connection?

See step 4: https://www.adaxes.com/help/ManageAndAutomateOffice365/

Are both required?

What permissions are needed for the User Account? Can we restrict permissions more with a User Account instead of an Application Account?

ago by (580 points)

1 Answer

ago by (310k points)
0 votes

Hello,

What permissions are needed for the User Account?

The account must be assigned the Global Administrator or both the User Administrator and Exchange Administrator roles in Microsoft Entra. Unfortunately, there is no possibility to be more granular about permissions in case of a user account.

Can we restrict permissions more with a User Account instead of an Application Account?

With all the limitations Microsoft are introducing for their APIs, it is highly recommended to use an application account. Also, it is very likely that user accounts will be decommissioned for such connections.

Related questions

we've migrated over to Application ID authentication...can this be updated to utilize this instead?

asked Oct 21, 2021 by jlaquatra (20 points)
0 votes
1 answer

AD is our identity source for Okta. When a user's AD account locks, the corresponding Okta account locks too. When the user self-unlocks the AD account via Adaxes, the ... there a way where Adaxes can also unlock the Okta account by leveraging Okta's API?

asked May 14, 2024 by ma4997 (20 points)
0 votes
1 answer

When Adaxes runs the command "Deactivate Microsoft 365 account of the user: set Sign-In status to 'Blocked', revoke all licenses" also revoke the sessions in Azure? For reference, it is the "Revoke sessions" button in the Azure portal:

asked Nov 22, 2024 by jmatthews (270 points)
0 votes
1 answer

Hi, our user objects are synced from HR system into AD and generated by a middleware - would a business rule "After creating a user" be triggered in this way or not? Looks ... for this? I need to control those tasks and would like to exit in case of issues

asked Jun 5, 2023 by wintec01 (2.7k points)
0 votes
1 answer

We would like the membership in a distribution group to be based on a particular M365 license a user has (for example, Microsoft Copilot for Microsoft 365 (SKU part number ... the group. Is there way to do that by making it a rule-based group?

asked Mar 11 by RayBilyk (310 points)
0 votes
1 answer