The Data & More Compliance Solution (DMCS) connects to Microsoft 365 through an app registration in your Entra ID tenant. You can choose between four ways to connect. They differ in what Data & More is allowed to do, from read-only scanning to real-time data loss prevention. This article explains each option and every permission it asks for.
Demo: read-only scan of mail and files. Good for a trial.
Production: full scanning plus policy actions on mail, files and Teams.
Production + DLP: everything in Production plus real-time DLP and Copilot.
Add App Registration: you create and control your own app registration.
How consent works
In Data & More, go to Settings β App registration. The four buttons at the top are the four options: Demo, Production, Production + DLP and Add App Registration. The first three use an app registration that Data & More maintains: select the button to get a consent link, and a Microsoft 365 administrator approves the permissions for your whole organisation. If you are not an administrator yourself, the same screen gives you an invitation e-mail to send to one.
All permissions in the first three options are application permissions. Data & More acts as a service, not as a signed-in user, so scanning keeps working when people are away and nobody's personal password is involved. You can see and revoke the granted permissions at any time in the Entra admin center under Enterprise applications.
Write permissions do not mean automatic deletion. Deletions go through a human approval step in Data & More before anything is removed.
Who needs to approve
Global Administrator or Privileged Role Administrator: approves the app permissions (all options).
Exchange Administrator (or Global Administrator): the one-time "Grant Exchange access" step in Production + DLP.
Teams Administrator (or Global Administrator): the one-time "Install Teams bot" step in Production + DLP.
What each option can do
Capability | Demo | Production | Production + DLP | Add App Registration |
|---|---|---|---|---|
Scan Outlook mail | Yes | Yes | Yes | You choose |
Scan OneDrive and SharePoint files | Yes | Yes | Yes | You choose |
Scan Teams channels and chats | No | Yes | Yes | You choose |
Recognise known people from Outlook contacts | No | Yes | Yes | You choose |
Read your sensitivity labels (Purview) | Yes | Yes | Yes | You choose |
Send reports and notifications by e-mail | Yes | Yes | Yes | You choose |
Policy actions: move to vault, delete, restore, tag, apply labels | No | Yes | Yes | You choose |
Real-time DLP on e-mail, files and Teams | No | No | Yes | You choose |
Copilot prompts and responses | No | No | Yes | You choose |
Alerts in Teams from the Data & More bot | No | No | Yes | You choose |
Who maintains the app registration | Data & More | Data & More | Data & More | You |
Access to your data | Read only | Read and write | Read and write | As you grant |
You can move to a larger option later. Select the larger option's button in Settings and approve again; the extra permissions are added to the existing app.
Option 1: Demo (read only)
The smallest set. Data & More reads mailboxes and files to show you where personal and sensitive data sits, but it cannot change anything in your tenant. Use it for a trial or a first assessment.
Covers: Outlook, OneDrive and SharePoint files.
Changes data: no, reports only.
Approval: Global Administrator, one click.
Permission | Access | What Data & More uses it for |
|---|---|---|
| Read | Reads the list of users and their basic profile (name, e-mail, department, manager), so it knows whose mailboxes and OneDrives to scan and who owns the data it finds. |
| Read | Reads groups and group membership, your organisation name and verified domains, and which permissions were granted. Used for group-based scoping and the Check Permissions button. |
| Read | Reads e-mails and attachments so they can be scanned for personal and sensitive data. |
| Read | Reads files in OneDrive and SharePoint, and who they are shared with, so they can be scanned. |
| Read | Reads your Microsoft Purview sensitivity labels, so findings can be compared with how data is labelled. |
| Send | Sends Data & More reports and notifications from a mailbox you choose. It does not read or change existing mail. |
Option 2: Production (read and write)
For day-to-day use. Data & More scans all of Microsoft 365, including Teams, and carries out the policies you set up: moving sensitive mail and files to a vault, deleting data past its retention date, restoring it, tagging it and applying sensitivity labels. All permissions are required.
Covers: Outlook, OneDrive, SharePoint and Teams.
Changes data: only when a policy you configured says so.
Approval: Global Administrator, one click.
Microsoft Graph
Permission | Access | What Data & More uses it for |
|---|---|---|
| Read | Users and basic profile, licences and photos: whose data to scan and who owns it. |
| Read | Groups and membership, Teams and their channels, organisation details, and the permission check. |
| Read and write | Scans e-mails and attachments. Policies can move mail to the |
| Read and write | Creates the Outlook categories used for tagging, and tells shared mailboxes from personal ones. |
| Send | Sends reports and notifications from a mailbox you choose. |
| Read | Reads Outlook contacts, so external people your employees work with are recognised as known persons. |
| Read and write | Scans OneDrive, SharePoint and Teams files. Policies can move files to a vault folder, delete or restore them, and apply a sensitivity label. |
| Read and write | Finds SharePoint sites and document libraries, writes Data & More metadata into library columns, and restores files from the recycle bin. |
| Manage | Adds the Data & More metadata columns to document libraries when a policy needs them. |
| Read | Reads basic information about Teams. |
| Read | Reads posts and replies in Teams channels so they can be scanned. |
| Read | Reads 1:1 and group chats in Teams so they can be scanned. |
| Read | Reads your sensitivity labels, so policies can apply them and findings can be compared with them. |
SharePoint
These three are granted on the SharePoint API rather than Microsoft Graph. They are used to read site groups and site owners, so findings on a site go to the people responsible for it.
Permission | Access | What Data & More uses it for |
|---|---|---|
| Read | Reads SharePoint site groups and their members. |
| Manage | Reads a site's owner group. |
| Read | Resolves SharePoint users to people in your directory. |
Scanning the Exchange Online Archive
The Online Archive is read through Exchange Web Services (EWS), which is not covered by any of the packages. If you want to scan it, also grant the Office 365 Exchange Online application permission full_access_as_app.
Option 3: Production + DLP (read and write)
Everything in Production, plus real-time data loss prevention. Microsoft 365 notifies Data & More the moment an e-mail is sent, a file is shared or a Teams message is posted. Data & More checks it against your DLP policies and can alert, hold or block it within seconds. It also covers Microsoft 365 Copilot and can alert users through a Teams bot.
Covers: Production, plus real-time DLP and Copilot.
Changes data: blocks, holds or restricts sharing when a DLP policy matches.
Approval: Global Administrator, plus up to three one-time steps.
In addition to all Production permissions
Permission | API | Access | What Data & More uses it for |
|---|---|---|---|
| Microsoft Graph | Read | Reads Microsoft 365 Copilot prompts and responses so they can be checked for sensitive data. Each user needs a Microsoft 365 Copilot licence. |
| Microsoft Graph | Read | Searches the audit log for Copilot Chat and agent activity that the Copilot export does not include. |
| Microsoft Graph | Read | Finds the Data & More DLP bot in your Teams app catalog. |
| Microsoft Graph | Install | Installs the Data & More DLP bot for users in scope, so it can send them alerts in a 1:1 chat. |
| Microsoft Graph | Install | Installs the bot in Teams where channel alerts are needed. |
| Office 365 Exchange Online | Manage | Creates and maintains the mail-flow rules that hold outgoing e-mail to external recipients until it has been checked. Data & More only manages its own rules. |
One-time setup steps
Some actions cannot be granted as app permissions. You complete them once from the DLP page, signed in as an administrator.
Step | Who signs in | What it grants |
|---|---|---|
Grant Exchange access | Exchange Administrator or Global Administrator | Signs in with the delegated |
Install Teams bot | Teams Administrator or Global Administrator | Uses the delegated |
Allow Teams message deletion (optional) | Global Administrator, or each message author | Microsoft only lets a Teams message be deleted on behalf of its author. Approving the delegated |
Copilot DLP is alert-only: Data & More can notify about a risky Copilot conversation but does not change it.
Option 4: Add App Registration (your own app)
Some organisations prefer to create the app registration in their own tenant, so they own the credentials and decide exactly which permissions to grant. Data & More then uses that app instead of its own. Grant only what the sources and features you plan to use need; the table at the end of this section lists the minimum for each.
1. Register the app
Sign in to portal.azure.com as a Global Administrator.
Search for App registrations and select New registration.
Enter a name (for example Data & More DMCS) and choose Accounts in this organizational directory only.
Under Redirect URI, choose Web and enter
https://signup.dataandmore.com/api/authorized.Select Register.
Open Authentication and add two more Web redirect URIs:
https://signup.dataandmore.com/api/authorize_redirectand your Data & More server address followed by/api/auth/ad/login/authorized. If your server ishttps://gdpr.dataandmore.com, that ishttps://gdpr.dataandmore.com/api/auth/ad/login/authorized. Select Save.
Always add both signup.dataandmore.com addresses, whichever package you use. They are needed for the consent and sign-in steps.
2. Add the API permissions
Open API permissions and select Add a permission β Microsoft Graph β Application permissions. Add the Graph permissions for your package (Demo, Production or Production + DLP above), or the minimum set for the features you want from the table below.
SharePoint (Production and Production + DLP): select Add a permission again, open APIs my organization uses, search for SharePoint, and add the three SharePoint application permissions.
Exchange (Production + DLP, or Online Archive): select Add a permission β APIs my organization uses, search for Office 365 Exchange Online, and add
Exchange.ManageAsApp(DLP) and/orfull_access_as_app(Online Archive).Select Grant admin consent and confirm. Every permission should now show a green Granted status.
3. Create the credentials
On the app's Overview page, note the Application (client) ID and the Directory (tenant) ID.
Open Certificates & secrets β New client secret, add a description and expiry date, and select Add.
Copy the secret Value straight away. It is only shown once, and you need the value, not the secret ID. Alternatively, upload a certificate; a certificate is required to read SharePoint site groups and owners.
4. Connect it to Data & More
In Data & More, open Settings β App registration β Add App Registration and enter the tenant ID, client ID and the secret value or certificate. If you cannot do this yourself, send the three values to support@dataandmore.com through a secure channel.
Select Check Permissions. Data & More lists which permissions it found, flags any that are missing, and shows when the secret or certificate expires.
Minimum permissions per feature
Feature | Scan (read) | Policy actions (write) |
|---|---|---|
Always needed |
| None |
Outlook |
|
|
Exchange Online Archive | Exchange: | Exchange: |
OneDrive |
|
|
SharePoint |
|
|
Teams channels |
|
|
Teams chats |
| None |
Known persons |
| None |
Sensitivity labels |
|
|
Reports by e-mail | None |
|
Copilot |
| None |
Real-time DLP | The scan permissions of each source you protect | Exchange: |
Keep in mind: you are responsible for renewing the secret or certificate before it expires; the Check Permissions view shows the expiry date. If a permission is missing, the related source shows an access error instead of failing silently. Add the permission, grant admin consent again, and run Check Permissions.
Limit what Data & More can reach
Application permissions apply to the whole tenant. If you want to narrow them, Microsoft offers these controls, and Data & More works with all of them:
Scope in Data & More. Choose which users, groups, sites and Teams each source covers. Nothing outside the scope is scanned or changed.
Exchange application access policy or RBAC for Applications. Restrict
Mail.Sendand mailbox access to a mail-enabled security group.Audit. Every call Data & More makes appears in your Entra sign-in logs and the Microsoft 365 audit log under the app's name.
Common questions
Can Data & More read my users' passwords?
No. None of these permissions give access to passwords or sign-in credentials. Data & More authenticates as its own app, with its own secret or certificate.
Why does a read-mostly product need write permissions?
Write access is only used when a policy you configured tells Data & More to act, for example to move a sensitive file to a vault or delete e-mail past its retention date. Deletions also go through a human approval step. If you only want reports, choose Demo, or grant read permissions only in your own app.
Can we start with Demo and upgrade later?
Yes. Select Production or Production + DLP in Settings β App registration and approve again. Your existing scan results are kept.
What happens if we remove a permission?
The features that depend on it stop, and the affected sources show an access error. Everything else keeps working. Run Check Permissions to see what is missing.
Does Data & More use delegated (signed-in user) permissions?
None of the three packages contains delegated permissions, not even User.Read. Delegated permissions are only used for the one-time DLP steps, for personal accounts (where a user connects their own mailbox and OneDrive), and for deleting Teams messages, which Microsoft allows only on behalf of the author.
I lost the client secret. Can I see it again?
No. Microsoft shows a client secret value only once, right after you create it. Create a new secret, update it in Settings β App registration, and delete the old one.