Skip to content
English
  • There are no suggestions because the search field is empty.

I've onboarded read only but see a RW app too

Some client observed the [ATTIC] M365 RW app in their tenant even after onboarding using the read only option.

To enable "Read Only" access for Microsoft 365, Exchange Online requires specific Entra ID roles that cannot be granted through a standard app consent screen.

To keep onboarding seamless, we use a temporary app called "[ATTIC] M365 RW". This app requests delegated permissions, allowing us to assign the necessary roles on your behalf during setup.

Will Attic have write permissions forever? No. Because these are delegated permissions (linked to the specific user who signs in), we cannot perform actions indefinitely. Once the initial setup is complete, we delete the access tokens. We cannot re-access your environment unless the original admin manually clicks the onboarding link again.

How can I verify this? You can audit these permissions at any time:

  1. Go to Entra ID > Enterprise applications.

  2. Search for the "[ATTIC] M365 RW" app.

  3. Navigate to Security > Permissions to view the active delegated permissions.

  4. Select the User Consent tab