Changelog | Ampersand - Onboard a whole Microsoft tenant with one admin approval

Onboard a whole Microsoft tenant with one admin approval

Enterprise agents often need access to not just a single user’s data but an entire organization’s data for a specific resource. Previously every user was required to login and click through consent OAuth popups. When a single user denies access, permissions and gaps in data becomes a headache. Onboarding cost scales with number of end customers.

Alternatives might include running a legacy workaround like Exchange Web Services (EWS) impersonation, which gives a service account all access permissions to act as any user in an organization. With limited security control, enterprise agents still on EWS may have no guardrails inside the mailboxes they reach and can risk exposing sensitive data.

Ampersand now supports Microsoft (Admin consent), where one tenant administrator grants consent once for the whole organization. Your integration then calls the Microsoft Graph API as an application, with no individual user signing in. With Admin consent, scopes are granular and require approval for specific permissions.

Per-user OAuth
Consent grants needed
One consent popup per end user. Onboarding cost scales with customer headcount.
Admin consent
1 tenant administrator
Consent grants needed
One approval covers the tenant. Ampersand then calls Graph as the application, so nobody else has to sign in.

What the connector supports

  • Read actions: including full historic backfill and incremental read.
  • Write actions: create and update records through Graph.
  • Proxy actions: call any Graph endpoint yourself, using the base URL https://graph.microsoft.com.

Because consent is granted at the tenant level, the object surface is Graph itself: users, groups, calendars, events, messages and many more.

Pick the right Microsoft connector

Both connectors stay available, and they answer different questions about whose data you are reading.

Start building
deep integrations today