This article contains the required Microsoft integrations for Neos and Microsoft permissions. This information can also be accessed in the attached PDF.
Required Integrations
The following integrations are required to use Neos and perform functions within Calendar, Documents, Texting, and Emails.
Microsoft 365® Email
The Neos Calendar requires a Microsoft 365® Outlook Email Mailbox for each user. Additionally, the Microsoft 365® Integration requires activation by a designated Global Admin account. Each user's Outlook email must be activated in their Staff Profile, which is also used to send texts and email from Neos.
Recommended: New Global Admin Account – Using a new Global Admin Account reduces the risk of the account becoming compromised or disabled and lists file activity associated with Neos to the Global Admin Account.
Microsoft 365® SharePoint
Documents relating to a Case, Provider, or Template are stored on your firm's Microsoft 365® SharePoint site. Your firm's CloudDocs site will contain three document libraries: CaseFiles, ProviderFiles, and TemplateFiles.
Required: Microsoft 365® (Business Basic*, Business Standard**, Business Premium, Office 365 E3, or Office 365 E5)
*Business Basic must include Exchange and SharePoint
**Business Standard or higher also includes desktop, web, and mobile apps
Recommended: Neos Integrations Staff (marked Active and non-activated Email) with Full Permissions (Enabled, Add, Modify, and Delete)
OneDrive® Integration
Neos connects with your firm's OneDrive®, which is used for adding and generating Case or Provider documents that can be viewed and edited directly in your firm's SharePoint.
Recommended: New Global Admin Account – Using a new Global Admin Account reduces the risk of the account becoming compromised or disabled and lists file activity associated with Neos to the Global Admin Account.
Microsoft Permissions
Permission Overview
Upon enablement of the Microsoft integration for both the firm and users, specific permissions are requested under the following two categories: Application and Delegated.
Application Permissions: These permissions are utilized by Neos independent of a user and granted by a Microsoft Global Administrator.
Delegated Permissions: These permissions are utilized by Neos on behalf of a user. Neos can only do what the user has permissions to do. Although a permission is listed in the delegated category, if the user does not actually have permissions to complete the function within Microsoft, then Neos will not be able to complete that function.
Permissions Requested
Type | Permission | Description | Why it is needed | |
Application | Directory.ReadWrite.All | Read and write directory data | Must have to create a SharePoint site from OneDrive integrations page | |
Application | Group.ReadWrite.All | Read and write all groups | Must have to create a SharePoint site from OneDrive integrations page | |
Application | Sites.ReadWrite.All | Read and write items in all site collections | Neos uses this scope to access and update documents and folders from within Neos. Since you can modify the site and folders utilized within Neos at any time, all sites are required. | |
Application | Sites.Manage.All | Create, edit, and delete items and lists in all site collections | Must have to create a SharePoint site from OneDrive integrations page | |
Type | Permission | Description | Why it is needed | Why it is needed |
Application | Calendars.Read | Read calendars in all mailboxes | Reporting on calendar events | Reporting on calendar events |
Application | Calendars.ReadWrite | Read and write calendars in all mailboxes | Integrations leveraging calendar require this to be able to create events. | Integrations leveraging calendar require this to be able to create events. |
Delegated | Calendars.ReadWrite | Have full access to user calendars | Viewing and modifying calendars that the user has edit access to in Outlook | Viewing and modifying calendars that the user has edit access to in Outlook |
Delegated | Directory.AccessAsUser.All | Access directory as the signed in user | Used for navigating through Entra Directory Users & Groups | Used for navigating through Entra Directory Users & Groups |
Delegated | Directory.ReadWrite.All | Read and write directory data | Used for navigating through Entra Directory Users & Groups. Write operations reserved for future use. | Used for navigating through Entra Directory Users & Groups. Write operations reserved for future use. |
Delegated | Files.ReadWrite | Have full access to user files | Neos uses this scope for user's token to access files in specific workflows as a failover if the user does not have write permissions, so that they can view the file. | Neos uses this scope for user's token to access files in specific workflows as a failover if the user does not have write permissions, so that they can view the file. |
Delegated | Files.ReadWrite.All | Have full access to all files user can access | Neos uses this scope for user's token to access and modify files in specific workflows. | Neos uses this scope for user's token to access and modify files in specific workflows. |
Delegated | Group.ReadWrite.All | Read and write all groups | When creating a SharePoint site from OneDrive integrations page | When creating a SharePoint site from OneDrive integrations page |
Delegated | Mail.Read | Read user mail | Must have to read emails within Neos | Must have to read emails within Neos |
Delegated | Mail.ReadWrite | Read and write access to user mail | Must have to modify emails within Neos | Must have to modify emails within Neos |
Delegated | Mail.Send | Send mail as a user | Must have to send emails within Neos | Must have to send emails within Neos |
Type | Permission | Description | Why it is needed |
Delegated | Sites.Manage.All | Create, edit, and delete items and lists in all site collections | Must have to create a SharePoint site from OneDrive integrations page |
Delegated | Sites.ReadWrite.All | Edit or delete items in all site collections | When SharePoint files are created or view from within Neos |
Delegated | User.Read | Sign in and read user profile | Used to read user profile information |
Delegated | User.Read.All | Read all users' full profiles | Used to read user profile information |
Delegated | User.ReadBasic.All | Read all users' basic profiles | Used to read user profile information |
Delegated | Calendars.ReadWrite.Shared | Read and write user and shared calendars | Viewing, creating, deleting, and modifying events on the calendars the user has edit access to. |
Revokable Permissions
Upon successful setup on the SharePoint site, the following application and delegated permissions can be revoked:
Application Permissions:
Directory.ReadWrite.All
Group.ReadWrite.All
Sites.Manage.All
Delegated Permissions:
Dreictory.ReadWrite.All
Directory.AccessAsUser.All
Directory.ReadWrite.All
Group.ReadWrite.All
