Set the permissions of the Microsoft 365 application for Token Vault

  1. Select API permissions in the menu on the left.
  2. Click the Add a permission button in the right panel to configure permissions for the application.
  3. Add those permissions only that are required.
    Different usage scenarios and components require different permissions. Add those permissions only that are required. To set up permissions for Unified Client workflows, do the following:
    1. Click the Microsoft Graph button under the Commonly used Microsoft APIs group on the Request API permissions page.
    2. Select Delegated permissions.
    3. Select the checkboxes beside the following permissions:
      • Microsoft Graph
      • Directory.Read.All
      • Directory.ReadWrite.All
      • User.Read
      • User.ReadWrite.All
      • Mail.Send
      • Mail.ReadWrite
      Admin consent is required to set the Mail.Readwrite permission.
    4. Click the Add permissions button.