Microsoft 365 admin consent guide
Audience: Microsoft Entra ID (Azure AD) administrators asked to approve Scale Platform’s access to Microsoft 365 files. All identifiers below are real and live. Maintained by Scale Company; questions to support@scale-company.com.
Scale Platform (app.scale-company.com) is a web application your colleagues sign in to directly. Nothing is installed into your tenant. Max Scale, its AI co-worker, evaluates complex transformation and innovation projects against supporting evidence. This request lets your team point it at documents that already live in Teams channels, SharePoint, and OneDrive, instead of uploading copies into Scale Platform.
Granting the consent below registers Scale Platform in your tenant as an enterprise application holding the read-only, user-delegated permissions listed here. It deploys nothing and changes nothing else in Microsoft 365.
Scale Company is ISO/IEC 27001:2022 certified (INTERCERT, reg. IC-IS-2605087) and all processing runs on Google Cloud in the EU. Our certificate, DPA, sub-processor list and security documentation are published at trust.scale-company.com.
What is being requested
Section titled “What is being requested”| Item | Value |
|---|---|
| Application | Scale Platform (Max Scale), application ID below, publisher-verified as Scale Company Oy. Max Scale is the AI co-worker inside Scale Platform; the registration carries both names. |
| Permission type | Delegated only, no application permissions. Scale Platform acts as the signed-in user, never as the tenant. |
| Consent needed | Tenant admin consent (most enterprise tenants disable individual user consent) |
Application ID:
740293f0-14e5-4175-88d0-4ff2070772e7Each permission, what Microsoft calls it on the consent screen, and why it is needed:
| Permission | Shown on the consent screen as | Why it is needed |
|---|---|---|
Files.Read.All |
Read all files that user can access | Read the documents your team links. The narrower Files.Read reaches only personal OneDrive and cannot read Teams or SharePoint libraries, the main use case. |
Sites.Read.All |
Read items in all site collections | List SharePoint sites in the file picker so users can browse to a file. Adds no file access beyond Files.Read.All. |
Team.ReadBasic.All |
Read the names and descriptions of teams | List the user’s own teams in the same picker. Team names only. |
offline_access |
Maintain access to data you have given it access to | Keep the connection working without re-prompting the user at every use. |
User.Read |
View users’ basic profile | Identify the connecting user. Reads their own profile only, nobody else’s. |
openid |
No separate line: the screen shows five entries, not six | Standard sign-in scope. |
Why these scopes, and not narrower ones
Section titled “Why these scopes, and not narrower ones”These scopes are broader than what Scale Platform actually reads, and we would rather say so
plainly. Files.Read.All lets the app read anything the signed-in user can already open, and
Sites.Read.All additionally covers SharePoint list items. In practice, Scale Platform reads only
the documents your team explicitly links, plus site and library names for the file picker. That
restraint is product behavior, not something the scope enforces.
What the permission model does enforce is the user boundary: both scopes are delegated, so access can never exceed what the signed-in user can see. Tenant-wide reading would require the application permission of the same name, which Scale Platform does not request.
The narrower alternatives do not currently work on Microsoft 365:
Files.Readreaches only the user’s personal OneDrive, not the Teams and SharePoint libraries where project evidence actually lives.Files.SelectedOperations.Selected, Microsoft’s per-folder grant model, has no admin UI: every folder is granted and revoked individually through Graph or PowerShell, and the app cannot browse anything not already granted. Each folder your team wants to link becomes an admin request, so we do not currently offer it.
A narrower scope also would not remove this consent step. Enterprise tenants generally disable user consent, so any delegated file scope needs the same one-time tenant-admin consent. There is no self-service tier to fall back to.
If this distinction matters to your review, we are happy to have a call. And if structurally enforced selection is a hard requirement rather than a preference, say so: we would want to understand what it has to guarantee for you, and whether you are willing to carry the administration it creates.
Not requested: any application (tenant-wide) permission, Group.Read.All, any SharePoint-API
scope, any write scope. Everything above is delegated and read-only, so access is bounded twice: by
what the authorizing user can see, and by what your team explicitly links.
What Scale Platform does, and does not do, with this access
Section titled “What Scale Platform does, and does not do, with this access”- User-delegated, read-only. Scale Platform reads through the account of the person who links a folder and can never see more than they can. There is no tenant-wide or application-level access.
- Explicit linking only. Only the folders and files your team links to a project are read. There is no crawl. Change detection uses Microsoft Graph delta queries scoped to those folders.
- No copies stored. Scale Platform stores references (item IDs, names, version info), not file contents. Content is fetched at evaluation time, processed, and discarded. Meeting recordings and transcripts saved to OneDrive or SharePoint can be included by linking the folder they land in.
- A short classification is kept beside the reference. After reading a document, Max records its kind, the dates it covers, its language and length, and what it is evidence for. It adds a one-line note of what the document is for, at most 200 characters. Never the content. Max is told not to write a person’s name into that note, and a note that names one is dropped before it is stored. A person may also attach a short note of their own to a file, stored as typed. All of it is deleted with the file, when the folder is unlinked, and when the connection is revoked.
- Tokens. Refresh tokens are stored encrypted (envelope encryption, Google Cloud KMS), decryptable only by Scale Platform’s backend, access-audited, and revocable.
Admin steps (one time)
Section titled “Admin steps (one time)”Option A: consent URL (recommended)
Section titled “Option A: consent URL (recommended)”Open this URL as a Global Administrator or Privileged Role Administrator, replacing
YOUR_TENANT_ID with your tenant ID:
https://login.microsoftonline.com/YOUR_TENANT_ID/adminconsent?client_id=740293f0-14e5-4175-88d0-4ff2070772e7Check the listed permissions against the table above, then accept.
Option B: Entra admin center
Section titled “Option B: Entra admin center”Open Enterprise applications in the Microsoft Entra admin center, or go to Entra ID → Enterprise apps → All applications. Search for the application ID, open the application, then Permissions → Grant admin consent. The application appears in this list after any user’s first sign-in attempt.
To limit who may use it, set Properties → Assignment required = Yes on the application and assign your pilot users or groups.
Afterwards each team member connects their own Microsoft account in Scale Platform, under Profile → Connected accounts → Microsoft 365 or from a project’s Files → Link files menu, and links folders. See Microsoft 365.
What your users will see
Section titled “What your users will see”Before you consent, anyone who tries to connect Microsoft 365 is stopped by an “Approval required” screen naming Scale Platform (Max Scale) from Scale Company Oy. Where your tenant has the admin consent workflow enabled, they can add a justification and request approval; nothing is granted until you act. They cannot override the screen themselves.
After you consent, that screen is gone, but each person still connects their own account. Your consent alone moves no data: Scale Platform sees nothing until someone connects and links a folder, and then only what that person can already see.
Revoking access
Section titled “Revoking access”- Whole tenant: Enterprise applications → the application → Permissions → revoke, or delete the service principal. All file access stops and linked folders show as disconnected in Scale Platform. If your organization also uses the Max Scale app for Teams chat, it is unaffected: chat does not use these permissions.
- Per user: Entra → the user → Revoke sessions, or the user disconnects Microsoft 365 in Scale Platform under Profile → Connected accounts.
- Per folder: anyone on the project team can unlink a folder at any time.
Refresh tokens also expire on their own after 90 days without use, on password reset (policy-dependent), or when the authorizing user is disabled.
Questions this guide should answer, and a contact for the rest
Section titled “Questions this guide should answer, and a contact for the rest”Security questionnaire, DPA, sub-processor list, ISO 27001 certificate, token-lifecycle documentation, and the design of the no-copies architecture are available from our trust center trust.scale-company.com and via support@scale-company.com.