Outlook App Permissions, Scope by Scope
Microsoft Graph permissions are more granular than Gmail's and the consent screen is less clear. Here is what each one lets an app do.
The Graph mail permissions that matter
- 1Mail.Read — read every message and attachment in your mailbox. No writes: it cannot categorise, move, draft or send.
- 2Mail.ReadWrite — read, create, update, move and delete messages, and manage categories and folders. Deletion under Graph moves items to Deleted Items rather than destroying them.
- 3Mail.Send — send mail as you. Microsoft keeps this separate from ReadWrite, so an app can hold write access without the ability to send, which is a genuinely useful distinction Gmail does not offer.
- 4MailboxSettings.Read and MailboxSettings.ReadWrite — your time zone, working hours, language, automatic replies and signature. ReadWrite can change your out-of-office.
- 5offline_access — the permission that lets the app keep working after you close the browser. Without it, access ends with the session.
- 6Delegated versus application permissions is the crucial split. Delegated means the app acts as you and can only reach your mailbox. Application permissions like Mail.Read as an app role reach every mailbox in the tenant and require admin consent — a categorically different grant.
- 7On a work or school account, your tenant admin may have to consent before you can connect anything, and may have granted consent on your behalf already.
What that actually means
- •The Microsoft consent screen lists permissions by display name, so Mail.ReadWrite and Mail.Send read as one vague blur
- •Nothing on the screen tells you whether a grant is delegated or tenant-wide unless you know to look for "consent on behalf of your organisation"
- •Admin-consented apps often cannot be removed by the user who uses them
- •Outlook categories created by an app persist in the mailbox after the app is removed
The exact scopes Clarity requests on Microsoft
- 1openid, email and profile — identity only, so Clarity knows which mailbox it is connected to.
- 2offline_access — so processing continues after you close the browser. Without it, labelling would stop the moment you logged out.
- 3Mail.ReadWrite — reading message bodies and attachments to classify them, applying Outlook categories, and creating and updating drafts in your Drafts folder.
- 4Mail.Send — required for sending, which happens only for actions you approve or workflows you deliberately configure. Send, reply, forward and scheduled send are classified HIGH risk in code and queued for approval rather than executed automatically.
- 5MailboxSettings.ReadWrite — reading your signature, time zone and working hours so drafts and scheduling proposals are correct for your mailbox.
- 6All of these are delegated permissions. Clarity does not request application permissions, so nothing it holds can reach a colleague's mailbox.
- 7One thing to know before you plan around it: Outlook support is not generally available yet. It is limited to an allowlist while calendar and multi-account handling are finished, and the connect is blocked for accounts outside it.
- ✓Delegated permissions only — the grant covers your mailbox and no one else's in the tenant
- ✓Mail.Send is held but gated by the same approval queue that gates sending on Gmail
- ✓MailboxSettings is used for signature and working hours, not to change your automatic replies
- ✓The GA status is stated up front rather than discovered after signing up
Who asks this
Microsoft 365 admin
Needs the literal permission list and confirmation that nothing requests application-level Mail.Read across the tenant.
Operations lead on Outlook.com
Wants categories applied automatically but no ability for the tool to send unprompted — Mail.Send is held, the approval queue is what constrains it.
Consultant on a client tenant
Needs to know whether admin consent is required before asking the client's IT team for anything.
Frequently asked questions
What is the difference between delegated and application permissions?
Delegated permissions let an app act as the signed-in user and reach only that user's mailbox. Application permissions let the app act as itself against every mailbox in the tenant and always require admin consent. Clarity requests delegated permissions only.
Why does Clarity request Mail.Send?
Because sending a scheduled reply or an approved draft is an actual send, and Microsoft keeps that permission separate from Mail.ReadWrite. Holding the permission is not the same as using it unprompted — send-class actions are classified HIGH risk and queued for approval before anything leaves.
Can Clarity change my automatic replies?
MailboxSettings.ReadWrite technically permits it, and we are not going to claim a permission is narrower than it is. Clarity uses it to read your signature, time zone and working hours. It does not set out-of-office.
Does this need my IT administrator's approval?
On a work or school tenant, often yes — many tenants require admin consent for any third-party app. On a personal Outlook.com account, you consent for yourself. Either way the permissions requested are the five listed above.
How do I remove Clarity's access to Outlook?
Disconnect in Clarity's Settings, then remove the grant at account.live.com/consent/Manage for a personal account, or via myapps.microsoft.com for a work account. If the app was admin-consented, an administrator removes it in Entra ID under Enterprise applications.
Reference: Microsoft Graph permissions reference
Related guides
Gmail App Permissions Explained
Every Gmail OAuth scope in plain English, and the exact five Clarity requests.
How to Revoke an App's Access to Gmail
The real steps to remove Gmail and Outlook app access — and what revoking does not delete.
AI Email Security: What to Check Before You Connect
The seven questions to ask an AI email vendor, and Clarity's answers to each.
What it costs you
Roughly 9.1 hours a week
Estimate2.8 hrs of that we could cover
The rest stays yours — it is not repeatable.
106 hrs
a year, if the low end of the range holds
137
threads went quiet and nothing told you
Last 90 days · your own mail · illustrative figures
Clarity Inbox
Get your free inbox report
An interactive report on your last 90 days: where your hours actually went, what is still waiting on you, and how much of your email could run itself. Free, delivered in minutes.
Get my free reportTakes 2 minutes · No credit card · Nothing is sent without you
.png?token=eyJraWQiOiJzdG9yYWdlLXVybC1zaWduaW5nLWtleV80NzQxMTM1Ny0yOWQ5LTRjYjctYTQ2ZS1iMWRhZTM5MGQxNjQiLCJhbGciOiJIUzI1NiJ9.eyJ1cmwiOiJXZWJzaXRlIEFzc2V0cy9jbGFyaXR5LWluYm94LWxvZ28tKGRhcmstaGlyZXMpLnBuZyIsImlhdCI6MTc3MDY2MjMyOSwiZXhwIjo0ODkyNzI2MzI5fQ.l97-jsT-3RFJHPguXJZtFfhnzBNV69xS0XwfvOXYci0)