For Microsoft administrators
Paginel connects to Microsoft 365 to open SharePoint and OneDrive documents on behalf of each person, with their own permissions. Here is each permission requested, when, and why.
The SharePoint connector is being prepared: this page describes what it will request. The consent link for your organisation will come with it.
The principle
- Delegated permissions only, one token per person: Paginel sees what the person sees, nothing more. No application permissions (without a user).
- Requested when needed, in two steps: the minimum at sign-in, then access to other people’s files the first time such a file is opened.
- Protected tokens: refresh tokens are encrypted on our side, can be revoked from the account, and are erased with it.
Step one: at sign-in
Each person can grant these alone, if your organisation allows it.
-
openid, profile - Sign you in with your Microsoft account and show your name.
-
offline_access - Keep you signed in without asking again every time (refresh token, encrypted on our side).
-
User.Read - Read your basic profile: name, address, organisation.
-
Files.ReadWrite - Open and save your own OneDrive files (with a personal account, also those shared with you).
-
Team.ReadBasic.All - List the teams you belong to, so you can pick a document there.
Step two: the first time someone else’s file is opened
-
Files.ReadWrite.All - Open a document from a team or a site the person has access to, and save the changes there in their name. Paginel uses it only for the documents the person opens.
Since 2025, Microsoft’s default policy reserves this permission for administrator approval in almost every organisation. A single approval covers the whole organisation; each person then keeps their own token.
What we do not request
- No application permissions: Paginel never acts without a signed-in person.
- No mail, no calendar, no contacts.
Sites.Read.Allis avoided. Should it become necessary (to list followed sites), it would be added here, with its reason, before being requested.- No SharePoint workaround scopes (
AllSites.*).
Granting consent for your organisation
You will be able to approve Paginel once for the whole organisation, or let your users request it: Entra’s admin consent request workflow will bring the request to you.
Good to know
- A document encrypted by a sensitivity label (Purview, IRM) does not open in Paginel; it says so clearly.
- A file open in Word may refuse a save (co-authoring lock): Paginel keeps the changes and retries later, never forcing.
- Microsoft publisher verification: [to be completed: status of publisher verification].
A question about a permission? Write to us.
Going further
- Data management Where your documents are, who can read them, how to take them back.
- Help The questions we are asked most.