Skip to main content

Capabilities

Structure Sync

AccessOwl periodically syncs the permissions schema of an application.

User Sync

AccessOwl periodically syncs a list of users along with their assigned permissions.

Provisioning

AccessOwl creates or removes user accounts with the specified permissions during access requests or revocations.Note: Distribution Groups cannot be automatically provisioned or deprovisioned due to API limitations at Microsoft. Only Roles, Licenses, and Security Groups can be managed.

Directory Sync

AccessOwl syncs (creates, removes, or deactivates) users from directories like Slack, Microsoft365, Okta, or Google into the AccessOwl users database.

Required Microsoft 365 OAuth Permissions

AccessOwl integrates with your Microsoft 365 / Entra ID tenant to automate user provisioning, de-provisioning, and directory sync. When you connect Microsoft as a directory, AccessOwl requests the following Microsoft Graph permissions. All of these are delegated permissions: AccessOwl acts on behalf of the admin who grants consent, using that admin’s own directory rights. They are not application permissions.

Which Entra role does the connected account need?

Because the permissions are delegated, AccessOwl can only perform the actions the connected admin account is itself allowed to perform in Entra ID. Connect with a Global Administrator account so every capability works.

FAQ

Order matters. Group memberships, Entra directory roles and licenses are removed first, then the account is suspended, so the paid seat is freed instead of staying assigned to a suspended user.Distribution Groups are the exception. They cannot be removed automatically because of API limitations at Microsoft, so remove those memberships yourself.Let the offboarding be the first thing that touches the account. Blocking sign-in in Microsoft does not release the license, it stays assigned and billed until it is removed. If someone blocks the account before the offboarding runs, the Microsoft 365 access drops out of AccessOwl on the next directory sync, so when the offboarding starts there is no access left to revoke and the license removal step has nothing to act on. The user still shows as removed in AccessOwl and the seat is still being paid for. For anyone offboarded this way, remove the license by hand in the Microsoft 365 admin center.
No. Microsoft 365 provisioning only creates the account and assigns licenses, Entra directory roles, and group memberships. AccessOwl never sets or changes Exchange mailbox or calendar folder permissions.A newly created mailbox keeps Microsoft’s own default: the calendar’s Default permission is set to AvailabilityOnly (free/busy). If your organization prefers a different org-wide calendar sharing level, apply it on the Microsoft side, as Exchange does not automatically push an org-wide default onto new mailboxes.
Last modified on September 18, 2026