Someone at your company wants to connect their Outlook to Sigbot, which builds a contact list from the email signatures in their mailbox. Microsoft has asked for an admin to approve it. This page covers what Sigbot reads, what it keeps and where, and how to approve or revoke it for the whole company.
It prints on one A4 page.
Mail.Read, User.Read, offline_access4cf71eb1-6fb9-4e5d-ae33-83dc7aad081b| Permission | Why |
|---|---|
Mail.Read | To read the signature at the bottom of each email. Read-only: Sigbot can't send, move or delete mail. |
User.Read | To know who connected: their name and email address. |
offline_access | To keep reading new mail without asking the person to sign in again each time. |
All three are delegated: Sigbot acts only for a person who signs in and connects their own mailbox. Approving Sigbot for the company does not let it read anyone else's mail.
Why not Mail.ReadBasic? It leaves out the message body, and the signature is in the body.
For each message Sigbot reads the body, sender, recipients, subject and date, to find the signature and to tell a real correspondent from a newsletter. It also checks who the person has recently written to (up to 200 sent messages). Attachments are never downloaded.
Microsoft's default consent setting (Let Microsoft manage your consent settings) stops ordinary users from giving an outside app access to their mail. So in most companies an admin approves Sigbot once, for everyone. Microsoft's screen shows Sigbot as a verified publisher (SIGBOT LTD), with Microsoft's blue badge.
You need to be a Global Administrator, Privileged Role Administrator, Cloud Application Administrator or Application Administrator.
Open Microsoft's approval page. The same link is on sigbot.co/it-admins.html and in the Need admin approval panel your colleague sees in Sigbot.
Admin for more than one Microsoft 365 organisation? Replace organizations in the link with your company's domain or tenant ID.
Turn on Microsoft's admin consent workflow: Entra admin centre → Enterprise applications → Consent and permissions → Admin consent settings → Users can request admin consent to apps they are unable to consent to → Yes, and choose reviewers. Your colleague then sees Request approval on Microsoft's screen, and a reviewer approves or denies it.
To limit Sigbot to certain people: Enterprise applications → Sigbot → Properties → Assignment required → Yes, then add them under Users and groups.
4cf71eb1-…) → Properties. Set Enabled for users to sign in? to No to stop it at once, or Delete to remove the app and every permission granted to it.Every team plan keeps a year of audit log, which owners and admins can export as CSV. Enterprise adds single sign-on (Entra ID, Okta or SAML), SCIM, audit log streaming and a read-only API, set up with you on a call: book one here.
Security questions: security@sigbot.co. Anything else: support@sigbot.co, or book a 20-minute call. We reply within one working day.
Sigbot Ltd · Registered in England and Wales, company no. 16997653 · ICO registration ZC202535 · Full detail: sigbot.co/legal/security.html and sigbot.co/legal/dpa.html · This brief: sigbot.co/it-admins.html