FAQ - BeZoned Application Permissions
General understanding
Microsoft 365 applications use a permission-based security model. Before an application can access information or perform actions on behalf of a user or an organization, the required permissions must be granted by the user or a Microsoft 365 administrator.
BeZoned integrates deeply with Microsoft Teams and Microsoft 365 to create a unified virtual office experience. Rather than requiring users to switch between Teams, Outlook, Planner, Whiteboard, Files, and other Microsoft applications, BeZoned brings these capabilities together in a single interface.
To provide this experience, BeZoned uses the Microsoft Graph API—the standard Microsoft interface for accessing Microsoft 365 services. Every permission requested by BeZoned corresponds to a documented Microsoft Graph permission and is required to enable one or more specific features within the application.
The sections below explain each permission requested by BeZoned, why it is needed, and which feature depends on it. Following Microsoft's principle of least privilege, BeZoned requests only the permissions necessary to deliver its functionality.
FAQ
How does BeZoned use my data?
How does BeZoned use my data?
BeZoned only uses data provided through the above Microsoft Graph permissions to deliver its online office functions. For example, it reads your presence so you can participate in discussions, and it create meetings only when you request one. The app does not access email contents, files or other data that are unrelated to online office operations. All data is processed in accordance with the BeZoned product privacy policy.
Why are there application permissions (app roles) instead of delegated permissions for some features?
Why are there application permissions (app roles) instead of delegated permissions for some features?
Some tasks – such as creating Teams, managing channels or installing tabs across an organization – must be performed by an app in the background without a user present. Microsoft Graph exposes these tasks as application permissions (also called app roles), so BeZoned needs administrator consent to perform them. For user‑level tasks (chatting, creating a meeting, etc.), the app uses delegated permissions and operates on behalf of the signed‑in user.
Does BeZoned send messages or change settings without my knowledge?
Does BeZoned send messages or change settings without my knowledge?
No. BeZoned will only send messages, create channels or update settings when triggered by the user or an administrator. For example, it might send a “Come join me in the kitchen channel” message when you click “Invite”, or it might update channel names when an admin renames BeZoned rooms. The app cannot silently access email or impersonate users outside of Teams.
What is the offline_access scope and why do you need it?
What is the offline_access scope and why do you need it?
offline_access is an OpenID Connect scope that allows an app to obtain refresh tokens so it can maintain access to the data you’ve authorized even when you’re not actively using the app. This does not give BeZoned any extra privileges; it simply means you won’t be repeatedly asked to sign in. Without it, the app would lose its token after an hour and interrupt the online office experience.
Can I remove some permissions?
Can I remove some permissions?
BeZoned requires all of the permissions listed to deliver the full online office experience. If you remove a permission (for example, by revoking Chat.ReadWrite or Presence.ReadWrite.All), certain features may stop working. However, you can restrict deployment to a subset of Teams or users through the Teams Admin Center and limit which channels BeZoned can access.
How do I grant these permissions?
How do I grant these permissions?
A tenant administrator must review the permission list in Azure AD/Entra ID and grant consent. During installation in the Teams Admin Center or via Microsoft AppSource, you will see the list of permissions described above. Once consent is granted, BeZoned will only use those permissions for features described in this FAQ.
Permissions needed
Microsoft recommends following the principle of least privilege, meaning that applications should request only the permissions that are necessary to provide their functionality.
BeZoned follows this principle. Rather than requesting a small number of broad permissions that grant extensive access, BeZoned requests a larger number of more specific permissions. This allows us to request only the access required for individual features, helping to minimize the overall level of access granted.
Below is a list of the Microsoft permissions that BeZoned requests to operate within Microsoft Teams and Microsoft 365, together with an explanation of why each permission is needed.