Microsoft 365 permissions
TeamOrgChart works on the minimal consent principle; you only need to provide permissions to enable the functionality you wish to use.
Some chart data sources and features require additional Microsoft Graph permissions. These permissions can only be granted by an account with the required Microsoft administrator rights.
Permissions can be granted from the Permissions Page or during chart creation when TeamOrgChart detects that a required permission has not yet been granted.
Permissions overview
| Feature | Role required | Scope(s) |
|---|---|---|
| Enable all TeamOrgChart features | Global admin | All scopes required by TeamOrgChart |
| Full Microsoft Entra org charts | Global admin | Directory.Read.All |
| Minimal Entra profile org charts | Global admin | User.ReadBasic.All |
| Excel workbook org charts from OneDrive | Global admin | Files.Read.All, Sites.Read.All |
| Security group chart access | Global admin | Directory.Read.All |
| Microsoft 365 user presence | Global admin | Presence.Read.All, User.ReadBasic.All |
| Directory user search and sharing | Global admin | User.ReadBasic.All |
| SharePoint list org charts | Global admin | Sites.Read.All |
| Calendar availability | Global admin | Calendars.Read, Calendars.Read.Shared, MailboxSettings.Read |
When permissions are needed
You can explore the demonstration chart without granting extra permissions. TeamOrgChart will ask for additional consent only when a feature needs access to Microsoft 365 data, such as creating a chart from Entra ID, a SharePoint list, or a workbook stored in OneDrive.
If your organization blocks user consent, ask a Microsoft 365 Global Administrator to grant the required permission from the Permission Settings page.