> For the complete documentation index, see [llms.txt](https://docs.easycallreport.easyplatform.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.easycallreport.easyplatform.app/administration/permissions.md).

# Permissions

Easy Call Report requires two separate app registrations within your tenant to ensure functionality and security:

1. **Easy Call Report**: This primary app handles the core functionalities, enabling the display of your contacts directly within Microsoft Teams.
2. **Easy Call Report Configuration**: To enhance security, a second app registration with elevated permissions is used to change the users configuration
3. **Easy Platform Configuration Center**: To enhance security, a third app registration with elevated permissions is used for configuration tasks. This app allows:
   * Access to auto attandants and call queues
   * The provision of a dedicated portal for managing auto attandants and call queues.

Access to the **Easy Platform Configuration Portal** is restricted to users assigned the **Teams Administrator** role, ensuring that only authorized personnel can manage the platform’s configuration and permissions.

This two-app approach guarantees both robust functionality and a secure management environment for Easy Directory.

### Easy Call Report App

<table><thead><tr><th width="206">Permission</th><th width="399.6666259765625">Description</th><th width="140.33349609375">Type<select><option value="kPvGpDYjuxPJ" label="Application" color="blue"></option><option value="2ps1lminZQoh" label="Delegated" color="blue"></option></select></th></tr></thead><tbody><tr><td>People.Read</td><td>Read the signed-in user's relevant people list (ranked contacts from multiple sources).</td><td><span data-option="2ps1lminZQoh">Delegated</span></td></tr><tr><td>Presence.Read.All</td><td>Read presence info for all users on behalf of signed-in user (activity, availability, status note, OOF, timezone, location).</td><td><span data-option="2ps1lminZQoh">Delegated</span></td></tr><tr><td>User.Read</td><td>Basic signed-in user profile.</td><td><span data-option="2ps1lminZQoh">Delegated</span></td></tr><tr><td>User.Read.All</td><td>Read full profiles of all users.</td><td><span data-option="2ps1lminZQoh">Delegated</span></td></tr><tr><td>User.ReadBasic.All</td><td>Read basic profiles (name, email, photo, etc.) of all users.</td><td><span data-option="2ps1lminZQoh">Delegated</span></td></tr><tr><td>CallRecord-PstnCalls.Read.All</td><td>Read all PSTN and Direct Routing call log data.</td><td><span data-option="kPvGpDYjuxPJ">Application</span></td></tr><tr><td>CallRecords.Read.All</td><td>Read call records for all calls and online meetings.</td><td><span data-option="kPvGpDYjuxPJ">Application</span></td></tr><tr><td>TeamworkActivity.Send</td><td>Send a teamwork activity (notification) to any user.</td><td><span data-option="kPvGpDYjuxPJ">Application</span></td></tr><tr><td>User.Read.All</td><td>Read profiles of all users without a signed-in user.</td><td><span data-option="kPvGpDYjuxPJ">Application</span></td></tr><tr><td>User.ReadBasic.All</td><td>Read basic profiles of all users without a signed-in user.</td><td><span data-option="kPvGpDYjuxPJ">Application</span></td></tr><tr><td></td><td></td><td></td></tr></tbody></table>

**Optional features**

<table><thead><tr><th width="206">Permission</th><th width="399.6666259765625">Description</th><th width="140.333251953125">Type<select><option value="kPvGpDYjuxPJ" label="Application" color="blue"></option><option value="2ps1lminZQoh" label="Delegated" color="blue"></option></select></th></tr></thead><tbody><tr><td>Tasks.ReadWrite</td><td><p><strong>Planner integration</strong></p><p>Sync Easy Call Report activities with Microsoft Planner when enabled.</p></td><td><span data-option="2ps1lminZQoh">Delegated</span></td></tr><tr><td>Tasks.ReadWrite</td><td><p><strong>Personal tasks</strong></p><p>Allow supervisors to manage personal tasks from Easy Call Report.</p></td><td><span data-option="2ps1lminZQoh">Delegated</span></td></tr><tr><td>Contacts.ReadWrite</td><td><p><strong>Personal contacts</strong></p><p>Allow supervisors to access and update personal contacts.</p></td><td><span data-option="2ps1lminZQoh">Delegated</span></td></tr><tr><td>Mail.Send</td><td><p><strong>Send mail from Easy Call Report</strong></p><p>Send emails directly from Easy Call Report analytics.</p></td><td><span data-option="2ps1lminZQoh">Delegated</span></td></tr><tr><td>Chat.Create, ChatMessage.Send</td><td><p><strong>Send chat from Easy Call Report</strong></p><p>Send Teams chat messages directly from Easy Call Report analytics.</p></td><td><span data-option="2ps1lminZQoh">Delegated</span></td></tr><tr><td><strong>Contacts.Read</strong> (Application) — on Easy Contact Sync</td><td><p><strong>Shared mailbox search</strong></p><p>Search and display contacts from a shared mailbox.</p></td><td><span data-option="kPvGpDYjuxPJ">Application</span></td></tr></tbody></table>

### Easy Call Report Admin (Configuration)

<table><thead><tr><th width="206.33331298828125">Permission</th><th width="400.3333740234375">Description</th><th width="141.33331298828125">Type<select><option value="TspUrft7xGYk" label="Application" color="blue"></option><option value="2dDZmLz2U7Tb" label="Delegated" color="blue"></option></select></th></tr></thead><tbody><tr><td>Group.Read.All</td><td>Read all groups.</td><td><span data-option="2dDZmLz2U7Tb">Delegated</span></td></tr><tr><td>offline_access</td><td>Allows issuing refresh tokens.</td><td><span data-option="2dDZmLz2U7Tb">Delegated</span></td></tr><tr><td>openid</td><td>OIDC scope for ID token.</td><td><span data-option="2dDZmLz2U7Tb">Delegated</span></td></tr><tr><td>profile</td><td>Standard profile claims (name, email, etc.).</td><td><span data-option="2dDZmLz2U7Tb">Delegated</span></td></tr><tr><td>Presence.Read.All</td><td>Read presence information of all users in your organization.</td><td><span data-option="2dDZmLz2U7Tb">Delegated</span></td></tr><tr><td>Team.ReadBasic.All</td><td>Read team names &#x26; descriptions.</td><td><span data-option="2dDZmLz2U7Tb">Delegated</span></td></tr><tr><td>User.Read</td><td>Basic signed-in user profile.</td><td><span data-option="2dDZmLz2U7Tb">Delegated</span></td></tr><tr><td>User.Read.All</td><td>Read all users' full profiles.</td><td><span data-option="2dDZmLz2U7Tb">Delegated</span></td></tr><tr><td>Channel.ReadBasic.All</td><td>Read channel names &#x26; descriptions.</td><td><span data-option="2dDZmLz2U7Tb">Delegated</span></td></tr><tr><td>Channel.ReadBasic.All</td><td>Read the names and descriptions of teams, on behalf of the signed-in user.</td><td><span data-option="TspUrft7xGYk">Application</span></td></tr><tr><td>Team.ReadBasic.All</td><td>List all teams.</td><td><span data-option="TspUrft7xGYk">Application</span></td></tr><tr><td>TeamsAppInstallation.ReadForTeam.All</td><td>Read installed Teams apps for all teams.</td><td><span data-option="TspUrft7xGYk">Application</span></td></tr><tr><td><strong>TeamsAppInstallation.ReadWriteAndConsentForTeam.All</strong></td><td>Manage install &#x26; permission grants for Teams apps for all teams.</td><td><span data-option="TspUrft7xGYk">Application</span></td></tr><tr><td><strong>TeamSettings.ReadWrite.All</strong></td><td>Read and change all teams' settings.</td><td><span data-option="TspUrft7xGYk">Application</span></td></tr><tr><td>user_impersonation</td><td>Access Microsoft Teams and Skype for Business data as the signed in user.</td><td><span data-option="2dDZmLz2U7Tb">Delegated</span></td></tr></tbody></table>

**Optional features**

<table><thead><tr><th width="205.66656494140625">Permission</th><th width="400.3333740234375">Description</th><th>Type<select><option value="SCahpwXbhYhz" label="Delegated" color="blue"></option></select></th></tr></thead><tbody><tr><td>Tasks.ReadWrite</td><td><p><strong>Planner integration configuration</strong></p><p>Allow administrators to configure Planner-based workflows for Easy Call Report.</p></td><td><span data-option="SCahpwXbhYhz">Delegated</span></td></tr></tbody></table>

### Easy Platform Configuration Center Admin

<table><thead><tr><th width="180">Permission</th><th width="402">Description</th><th>Type<select><option value="I3fXQlMw2hBp" label="Delegated" color="blue"></option></select></th></tr></thead><tbody><tr><td>Application.Read.All</td><td>Read applications and service principals on behalf of the signed-in user.</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>Presence.Read.All</td><td>Read presence information of all users in your organization.</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>email</td><td>View users' email address (OIDC email claim).</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>offline_access</td><td>Maintain access to data you have given it access to (issue refresh tokens).</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>openid</td><td>Sign users in (request ID token via OpenID Connect).</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>profile</td><td>View basic profile information.</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>User.Read</td><td>Sign in and read the signed-in user's profile.</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr><tr><td>User.Read.All</td><td>Read full profiles of all users in the organization.</td><td><span data-option="I3fXQlMw2hBp">Delegated</span></td></tr></tbody></table>

**Optional features**

<table><thead><tr><th width="180.333251953125">Permission</th><th width="402.3333740234375">Description</th><th>Type<select><option value="SCahpwXbhYhz" label="Delegated" color="blue"></option></select></th></tr></thead><tbody><tr><td>CrossTenantInformation.ReadBasic.All</td><td><p><strong>Reseller tenant name resolution</strong></p><p>Show customer tenant display names (instead of only tenant IDs) in reseller subscriptions.</p></td><td><span data-option="SCahpwXbhYhz">Delegated</span></td></tr></tbody></table>
