Skip to main content

Microsoft Integration Requirements & Permissions

This article contains the required Microsoft integrations for Neos and Microsoft permissions. This information can also be accessed in the attached PDF.

Required Integrations

The following integrations are required to use Neos and perform functions within Calendar, Documents, Texting, and Emails.

Microsoft 365® Email

The Neos Calendar requires a Microsoft 365® Outlook Email Mailbox for each user. Additionally, the Microsoft 365® Integration requires activation by a designated Global Admin account. Each user's Outlook email must be activated in their Staff Profile, which is also used to send texts and email from Neos.

Recommended: New Global Admin Account – Using a new Global Admin Account reduces the risk of the account becoming compromised or disabled and lists file activity associated with Neos to the Global Admin Account.

Microsoft 365® SharePoint

Documents relating to a Case, Provider, or Template are stored on your firm's Microsoft 365® SharePoint site. Your firm's CloudDocs site will contain three document libraries: CaseFiles, ProviderFiles, and TemplateFiles.

Required: Microsoft 365® (Business Basic*, Business Standard**, Business Premium, Office 365 E3, or Office 365 E5)

*Business Basic must include Exchange and SharePoint

**Business Standard or higher also includes desktop, web, and mobile apps

Recommended: Neos Integrations Staff (marked Active and non-activated Email) with Full Permissions (Enabled, Add, Modify, and Delete)

OneDrive® Integration

Neos connects with your firm's OneDrive®, which is used for adding and generating Case or Provider documents that can be viewed and edited directly in your firm's SharePoint.

Recommended: New Global Admin Account – Using a new Global Admin Account reduces the risk of the account becoming compromised or disabled and lists file activity associated with Neos to the Global Admin Account.

Microsoft Permissions

Permission Overview

Upon enablement of the Microsoft integration for both the firm and users, specific permissions are requested under the following two categories: Application and Delegated.

  • Application Permissions: These permissions are utilized by Neos independent of a user and granted by a Microsoft Global Administrator.

  • Delegated Permissions: These permissions are utilized by Neos on behalf of a user. Neos can only do what the user has permissions to do. Although a permission is listed in the delegated category, if the user does not actually have permissions to complete the function within Microsoft, then Neos will not be able to complete that function.

Permissions Requested

Type

Permission

Description

Why it is needed

Application

Directory.ReadWrite.All

Read and write directory data

Must have to create a SharePoint site from OneDrive integrations page

Application

Group.ReadWrite.All

Read and write all groups

Must have to create a SharePoint site from OneDrive integrations page

Application

Sites.ReadWrite.All

Read and write items in all site collections

Neos uses this scope to access and update documents and folders from within Neos. Since you can modify the site and folders utilized within Neos at any time, all sites are required.

Application

Sites.Manage.All

Create, edit, and delete items and lists in all site collections

Must have to create a SharePoint site from OneDrive integrations page

Type

Permission

Description

Why it is needed

Why it is needed

Application

Calendars.Read

Read calendars in all mailboxes

Reporting on calendar events

Reporting on calendar events

Application

Calendars.ReadWrite

Read and write calendars in all mailboxes

Integrations leveraging calendar require this to be able to create events.

Integrations leveraging calendar require this to be able to create events.

Delegated

Calendars.ReadWrite

Have full access to user calendars

Viewing and modifying calendars that the user has edit access to in Outlook

Viewing and modifying calendars that the user has edit access to in Outlook

Delegated

Directory.AccessAsUser.All

Access directory as the signed in user

Used for navigating through Entra Directory Users & Groups

Used for navigating through Entra Directory Users & Groups

Delegated

Directory.ReadWrite.All

Read and write directory data

Used for navigating through Entra Directory Users & Groups. Write operations reserved for future use.

Used for navigating through Entra Directory Users & Groups. Write operations reserved for future use.

Delegated

Files.ReadWrite

Have full access to user files

Neos uses this scope for user's token to access files in specific workflows as a failover if the user does not have write permissions, so that they can view the file.

Neos uses this scope for user's token to access files in specific workflows as a failover if the user does not have write permissions, so that they can view the file.

Delegated

Files.ReadWrite.All

Have full access to all files user can access

Neos uses this scope for user's token to access and modify files in specific workflows.

Neos uses this scope for user's token to access and modify files in specific workflows.

Delegated

Group.ReadWrite.All

Read and write all groups

When creating a SharePoint site from OneDrive integrations page

When creating a SharePoint site from OneDrive integrations page

Delegated

Mail.Read

Read user mail

Must have to read emails within Neos

Must have to read emails within Neos

Delegated

Mail.ReadWrite

Read and write access to user mail

Must have to modify emails within Neos

Must have to modify emails within Neos

Delegated

Mail.Send

Send mail as a user

Must have to send emails within Neos

Must have to send emails within Neos

Type

Permission

Description

Why it is needed

Delegated

Sites.Manage.All

Create, edit, and delete items and lists in all site collections

Must have to create a SharePoint site from OneDrive integrations page

Delegated

Sites.ReadWrite.All

Edit or delete items in all site collections

When SharePoint files are created or view from within Neos

Delegated

User.Read

Sign in and read user profile

Used to read user profile information

Delegated

User.Read.All

Read all users' full profiles

Used to read user profile information

Delegated

User.ReadBasic.All

Read all users' basic profiles

Used to read user profile information

Delegated

Calendars.ReadWrite.Shared

Read and write user and shared calendars

Viewing, creating, deleting, and modifying events on the calendars the user has edit access to.

Revokable Permissions

Upon successful setup on the SharePoint site, the following application and delegated permissions can be revoked:

Application Permissions:

  • Directory.ReadWrite.All

  • Group.ReadWrite.All

  • Sites.Manage.All

Delegated Permissions:

  • Dreictory.ReadWrite.All

  • Directory.AccessAsUser.All

  • Directory.ReadWrite.All

  • Group.ReadWrite.All

Did this answer your question?