> For the complete documentation index, see [llms.txt](https://docs.easycalling.easyplatform.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.easycalling.easyplatform.app/administration/permissions.md).

# Permissions

Easy Calling requires three separate app registrations within your tenant to ensure functionality and security:

1. **Easy Calling:** This primary app handles the core functionalities, enabling the display of your call directly within Microsoft Teams.
2. **Easy Calling Configuration**: To enhance security, a second app registration with elevated permissions is used to change the users configuration
3. **Easy Platform Configuration Center**: To enhance security, a third app registration with elevated permissions is used for configuration tasks.

## Easy Calling

<table><thead><tr><th width="239.99993896484375">Permission</th><th width="351.666748046875">Description</th><th width="156.6666259765625">Type<select><option value="LBoB86I6aHG2" label="Application" color="blue"></option><option value="IzcIhKz6t57U" label="Delegated" color="blue"></option></select></th></tr></thead><tbody><tr><td>ChannelMember.Read.All</td><td>Read the members of channels (on behalf of signed-in user).</td><td><span data-option="IzcIhKz6t57U">Delegated</span></td></tr><tr><td>Presence.Read.All</td><td>Read presence information for all users (on behalf of signed-in user).</td><td><span data-option="IzcIhKz6t57U">Delegated</span></td></tr><tr><td>User.Read</td><td>Basic signed-in user profile.</td><td><span data-option="IzcIhKz6t57U">Delegated</span></td></tr><tr><td>User.Read.All</td><td>Read full profiles of all users.</td><td><span data-option="IzcIhKz6t57U">Delegated</span></td></tr><tr><td>CallEvents.Read.All</td><td>Read call event information for all users.</td><td><span data-option="LBoB86I6aHG2">Application</span></td></tr><tr><td>Calls.AccessMedia.All</td><td>Direct access to media streams in a call.</td><td><span data-option="LBoB86I6aHG2">Application</span></td></tr><tr><td>Calls.Initiate.All</td><td>Initiate 1:1 outbound calls and transfer calls.</td><td><span data-option="LBoB86I6aHG2">Application</span></td></tr><tr><td>Calls.InitiateGroupCall.All</td><td>Initiate outbound group calls and add participants.</td><td><span data-option="LBoB86I6aHG2">Application</span></td></tr><tr><td>Calls.JoinGroupCall.All</td><td>Join group calls and scheduled meetings (as app with user privileges).</td><td><span data-option="LBoB86I6aHG2">Application</span></td></tr><tr><td>Calls.JoinGroupCallAsGuest.All</td><td>Join group calls and meetings anonymously (guest).</td><td><span data-option="LBoB86I6aHG2">Application</span></td></tr><tr><td>ChannelMember.Read.All</td><td>Read members of all channels (no user context).</td><td><span data-option="LBoB86I6aHG2">Application</span></td></tr><tr><td>Presence.Read.All</td><td>Read presence info of all users (no user context).</td><td><span data-option="LBoB86I6aHG2">Application</span></td></tr><tr><td>TeamworkActivity.Send</td><td>Send teamwork activity notifications to any user.</td><td><span data-option="LBoB86I6aHG2">Application</span></td></tr><tr><td>User.Read.All</td><td>Read profiles of all users without a signed-in user.</td><td><span data-option="LBoB86I6aHG2">Application</span></td></tr></tbody></table>

**Optional features**

<table><thead><tr><th width="180.333251953125">Permission</th><th width="402.3333740234375">Description</th><th width="165.3333740234375">Type<select><option value="SCahpwXbhYhz" label="Delegated" color="blue"></option><option value="QffOyasFYM4w" label="Application" color="blue"></option></select></th></tr></thead><tbody><tr><td>Tasks.ReadWrite</td><td><p><strong>Planner integration</strong></p><p>Sync Easy Calling activities with Microsoft Planner when enabled.</p></td><td><span data-option="SCahpwXbhYhz">Delegated</span></td></tr><tr><td>Tasks.ReadWrite</td><td><p><strong>Personal tasks</strong></p><p>Allow agents to manage personal tasks from Easy Calling.</p></td><td><span data-option="SCahpwXbhYhz">Delegated</span></td></tr><tr><td>Contacts.ReadWrite</td><td><p><strong>Personal contacts</strong></p><p>Allow agents to access and update personal contacts.</p></td><td><span data-option="SCahpwXbhYhz">Delegated</span></td></tr><tr><td>Mail.Send</td><td><p><strong>Send mail from Easy Calling</strong></p><p>Send emails directly from Easy Calling conversations.</p></td><td><span data-option="SCahpwXbhYhz">Delegated</span></td></tr><tr><td>Chat.Create, ChatMessage.Send</td><td><p><strong>Send chat from Easy Calling</strong></p><p>Send Teams chat messages directly from Easy Calling conversations.</p></td><td><span data-option="SCahpwXbhYhz">Delegated</span></td></tr><tr><td><strong>Contacts.Read</strong> (Application) — on Easy Contact Sync</td><td><p><strong>Shared mailbox search</strong></p><p>Search and display contacts from a shared mailbox.</p></td><td><span data-option="QffOyasFYM4w">Application</span></td></tr></tbody></table>

## Easy Calling Configuration

<table><thead><tr><th width="196.33343505859375">Permission</th><th width="413.66650390625">Description</th><th width="126">Type<select><option value="KAgyRaBh5tiE" label="Delegated" color="blue"></option><option value="qhbolpUPTjUo" label="Application" color="blue"></option></select></th></tr></thead><tbody><tr><td>Team.ReadBasic.All</td><td>Read team names and descriptions (basic team metadata).</td><td><span data-option="KAgyRaBh5tiE">Delegated</span></td></tr><tr><td>Channel.ReadBasic.All</td><td>Read channel metadata with user context.</td><td><span data-option="KAgyRaBh5tiE">Delegated</span></td></tr><tr><td>Group.Read.All</td><td>Read Microsoft 365 groups across the tenant.</td><td><span data-option="KAgyRaBh5tiE">Delegated</span></td></tr><tr><td>Presence.Read.All</td><td>Read presence for all users on behalf of the admin.</td><td><span data-option="KAgyRaBh5tiE">Delegated</span></td></tr><tr><td>User.Read.All</td><td>Read full user profiles with user context.</td><td><span data-option="KAgyRaBh5tiE">Delegated</span></td></tr><tr><td>offline_access</td><td>Allow Easy Calling admin to refresh access tokens.</td><td><span data-option="KAgyRaBh5tiE">Delegated</span></td></tr><tr><td>openid</td><td>Enable OpenID Connect sign-in for Easy Calling admin.</td><td><span data-option="KAgyRaBh5tiE">Delegated</span></td></tr><tr><td>profile</td><td>Request standard profile claims for Easy Calling admin.</td><td><span data-option="KAgyRaBh5tiE">Delegated</span></td></tr><tr><td>user_impersonation</td><td>Access Microsoft Teams and Skype for Business data as the signed in user.</td><td><span data-option="KAgyRaBh5tiE">Delegated</span></td></tr></tbody></table>

## Easy Platform Configuration Portal App

<table><thead><tr><th width="180">Permission</th><th width="402">Description</th><th width="166">Type<select><option value="I3fXQlMw2hBp" label="Delegated" color="blue"></option></select></th></tr></thead><tbody><tr><td>Application.Read.All</td><td>Read applications and service principals on behalf of the signed-in user.</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>Presence.Read.All</td><td>Read presence information of all users in your organization.</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>email</td><td>View users' email address (OIDC email claim).</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>offline_access</td><td>Maintain access to data you have given it access to (issue refresh tokens).</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>openid</td><td>Sign users in (request ID token via OpenID Connect).</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>profile</td><td>View basic profile information.</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>User.Read</td><td>Sign in and read the signed-in user's profile.</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>User.Read.All</td><td>Read full profiles of all users in the organization.</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr></tbody></table>

**Optional features**

<table><thead><tr><th width="180.333251953125">Permission</th><th width="402.3333740234375">Description</th><th>Type<select><option value="SCahpwXbhYhz" label="Delegated" color="blue"></option></select></th></tr></thead><tbody><tr><td>CrossTenantInformation.ReadBasic.All</td><td><p><strong>Reseller tenant name resolution</strong></p><p>Show customer tenant display names (instead of only tenant IDs) in reseller subscriptions.</p></td><td><span data-option="SCahpwXbhYhz">Delegated</span></td></tr></tbody></table>
