Appspace Passport can connect with Microsoft Entra ID to bring user information, including profile pictures, into Appspace. Before enabling the integration, your organization may want to understand whether it can approve only the permissions needed for profile photo synchronization.
Are all requested permissions required?
Yes. All permissions requested by the Appspace Passport Entra ID application are mandatory for the integration. The requested access includes permissions to:
- Read directory data
- Read and write directory data
- Read all users’ basic profiles
- Read all users’ full profiles
- Read and write all users’ full profiles
Can permissions be removed or limited?
No. Appspace Passport does not currently offer a reduced or configurable permission set. Individual permissions cannot be removed while continuing to use the integration.
This also applies when your organization’s primary goal is to synchronize user profile pictures. A separate least-privilege configuration for profile photos alone is not currently available.
What should administrators consider?
Your Microsoft Entra ID administrator should review and approve the complete set of requested permissions before enabling Appspace Passport. If your organization cannot approve the full permission set, the Passport integration cannot be used for profile photo synchronization.
If you need additional information for a security or compliance review, contact your Appspace representative.

