Sign in I have a code Request access Create my account My documents

For Microsoft administrators

Paginel connects to Microsoft 365 to open SharePoint and OneDrive documents on behalf of each person, with their own permissions. Here is each permission requested, when, and why.

Being prepared

The SharePoint connector is being prepared: this page describes what it will request. The consent link for your organisation will come with it.

The principle

  • Delegated permissions only, one token per person: Paginel sees what the person sees, nothing more. No application permissions (without a user).
  • Requested when needed, in two steps: the minimum at sign-in, then access to other people’s files the first time such a file is opened.
  • Protected tokens: refresh tokens are encrypted on our side, can be revoked from the account, and are erased with it.

Step one: at sign-in

Each person can grant these alone, if your organisation allows it.

openid, profile
Sign you in with your Microsoft account and show your name.
offline_access
Keep you signed in without asking again every time (refresh token, encrypted on our side).
User.Read
Read your basic profile: name, address, organisation.
Files.ReadWrite
Open and save your own OneDrive files (with a personal account, also those shared with you).
Team.ReadBasic.All
List the teams you belong to, so you can pick a document there.

Step two: the first time someone else’s file is opened

Files.ReadWrite.All
Open a document from a team or a site the person has access to, and save the changes there in their name. Paginel uses it only for the documents the person opens.

Since 2025, Microsoft’s default policy reserves this permission for administrator approval in almost every organisation. A single approval covers the whole organisation; each person then keeps their own token.

What we do not request

  • No application permissions: Paginel never acts without a signed-in person.
  • No mail, no calendar, no contacts.
  • Sites.Read.All is avoided. Should it become necessary (to list followed sites), it would be added here, with its reason, before being requested.
  • No SharePoint workaround scopes (AllSites.*).

Granting consent for your organisation

You will be able to approve Paginel once for the whole organisation, or let your users request it: Entra’s admin consent request workflow will bring the request to you.

Good to know

  • A document encrypted by a sensitivity label (Purview, IRM) does not open in Paginel; it says so clearly.
  • A file open in Word may refuse a save (co-authoring lock): Paginel keeps the changes and retries later, never forcing.
  • Microsoft publisher verification: [to be completed: status of publisher verification].

A question about a permission? Write to us.

Going further