It is recommended for Admins to perform the following steps from a Private browser session or a new browser, to avoid using their currently active Microsoft session.
Alternative setup outside of DustEntra admins can also decide to create the application in Entra themselves, and will need the following consent URL (example for Outlook+Sharepoint, tweak the scopes as needed with the following permission matrix)
The Dust-Tools Application in EntraID
When consenting on behalf of your organization, (or requesting your admin to do so) Dust will create an entreprise application in Entra. The following permissions will be requested by the app. In this case, the Delegated type means that even if the requested permission claim is high, it will be delegated to the user when using Dust. (ie. if a user cannot read chatMessages, they won’t be able to by using the Dust-Tools app)Outlook (MCP Tool) - delegated permissions
Mail.ReadWrite- Read and write user mailMail.ReadWrite.Shared- Read and write shared mailContacts.ReadWrite- Full access to user contactsContacts.ReadWrite.Shared- Read and write shared contactsUser.Read- Sign in and read user profileoffline_access- Maintain access to data
Outlook Calendar (MCP Tool) - delegated permissions
Calendars.ReadWrite- Read and write calendarsCalendars.ReadWrite.Shared- Read and write shared calendarsUser.Read- Sign in and read user profileMailboxSettings.Read- Read mailbox settingsoffline_access- Maintain access to data
Microsoft Drive (MCP Tool) - delegated permissions
User.Read- Sign in and read user profileFiles.ReadWrite.All- Full access to all files user can accessSites.Read.All- Read items in all site collectionsExternalItem.Read.All- Read items in external datasetsoffline_access- Maintain access to data
Microsoft Teams (MCP Tool) - delegated permissions
User.Read- Sign in and read user profileUser.ReadBasic.All- Read all users’ basic profilesTeam.ReadBasic.All- Read names and descriptions of teamsChannel.ReadBasic.All- Read channel names and descriptions [2,3]Chat.Read- Read user chat messagesChat.ReadWrite- Read and write user chat messagesChatMessage.Read- Read user chat messagesChatMessage.Send- Send user chat messagesChannelMessage.Read.All- Read user channel messagesChannelMessage.Send- Send channel messagesoffline_access- Maintain access to data
Microsoft Excel (MCP Tool) - delegated permissions
User.Read- Sign in and read user profileFiles.ReadWrite.All- Full access to all files user can accessSites.Read.All- Read items in all site collectionsoffline_access- Maintain access to data