Securing internet traffic from devices with identity-aware web filtering and threat protection
Request for Granular Permission Controls When Installing Outlook Plugins
Subject: Request for Granular Permission Controls When Installing Outlook Plugins
Hello,
I’m writing to request a change in how Microsoft 365 handles permissions for Outlook add-ins that use Microsoft Graph. Currently, when installing a plugin such as ChatGPT or Claude, users are not shown the specific Graph permissions being requested, nor are they given the ability to approve or deny individual permissions.
To restrict plugin access (for example, allowing Email + Calendar but blocking Contacts), I had to manually navigate to Entra → Enterprise Applications → Permissions and remove scopes like Contacts.Read. This process is buried deep in the admin portal and is far too technical for the average user.
Please consider adding a permission review screen during plugin installation that allows users or admins to:
- See all requested Graph permissions
- Approve or deny individual scopes
- Block sensitive scopes such as Contacts.Read or People.Read
- Apply a “Mail + Calendar only” privacy mode
This would make plugin installation safer, more transparent, and significantly easier for users.
Thank you, RB