Required Admin Consent for CyberGate
cybergate is a software as a service (saas) solution that sets up calls between microsoft teams users and connected session initiation protocol (sip) devices it can only do this after an administrator has granted admin consent for the permissions cybergate needs in your tenant this page lists those permissions, what each one does, and why cybergate requires it permissions requested by cybergate for cybergate to be able to call users, the following permissions must be granted to cybergate each one maps to a specific cybergate capability; without it, the related feature cannot function permission display name description reason calls accessmedia all access media streams in a call as an app allows the app to get direct access to media streams in a call, without a signed in user access to the media of the teams call is required to send it to the sip device and vice versa calls initiate all initiate outgoing 1 to 1 calls from the app allows the app to place outbound calls to a single user and transfer calls to users in your organization's directory, without a signed in user enables cybergate to set up a call to a teams user calls joingroupcall all join group calls and meetings as an app allows the app to join group calls and scheduled meetings in your organization, without a signed in user the app will be joined with the privileges of a directory user to meetings in your organization the cybergate 'meeting' feature needs to be able to join an existing meeting groupmember read all read all group memberships allows the app to read memberships and basic group properties for all groups without a signed in user log in to the portal based on group membership user readbasic all read all users' basic profiles allows the app to read a basic set of profile properties of other users in your organization without a signed in user includes display name, first and last name, email address, open extensions, and photo cybergate needs to look up users in the tenant microsoft entra id (formerly azure active directory) to find the matching teams user to call why the portal asks you to update consent cybertwice reviews the permissions cybergate asks for and removes any that are no longer needed over time this has made the required set smaller than it used to be microsoft entra id, however, stores the permissions your organization consented to at the moment consent was given when cybertwice stops asking for a permission, that does not shrink a grant that already exists in your tenant the older, broader set stays in place until an administrator grants consent again for that reason cybergate compares the permissions actually granted in your tenant against the set it needs today if your tenant still holds permissions cybergate no longer uses, the 'consent' tab under basic → global in the cybergate management portal shows a warning instead of the usual 'admin consent has been provided for this tenant' message for example the permissions that cybergate service requires have been reduced since your organization gave consent the 'user read all' permission has been replaced with the new and much more restricted 'user readbasic all' permission cybertwice strongly recommends consenting to this reduced set of permissions this is not an error, and nothing is broken cybergate keeps working normally the warning is a request to bring your tenant's grant back in line with what cybergate actually needs why you should act on it least privilege a permission that is granted can be used keeping a permission that cybergate does not use gives the cybergate service principal access to data and actions it has no reason to touch smaller impact if something goes wrong if the cybergate application were ever compromised, the damage is bounded by what your tenant granted it — not by what cybergate uses trimming the grant shrinks that boundary cleaner security reviews and audits broad application permissions such as user read all and domain read all are routinely flagged in entra id permission reviews, cis/iso audits and customer security questionnaires removing them takes the finding away instead of having to justify it nothing is lost the permissions being dropped are ones the cybergate service no longer needs, either because a narrower permission replaced them or because the information is now read on behalf of the administrator who is signed in updating consent does not disable any cybergate feature permissions cybergate no longer needs if your organization consented to cybergate some time ago, your tenant may still hold one or more of the permissions below these are the permissions the warning refers to permission what changed user read all replaced by the much more restricted user readbasic all cybergate only needs a user's basic profile to find the matching teams user to call; user read all additionally exposes the full profile of every user in the tenant domain read all still needed information, obtained a different way cybergate needs to know which domains are verified in your tenant, but the cybergate service no longer looks them up itself the management portal now reads them while an administrator is signed in, using that administrator's own sign in permissions, and passes them on to cybergate the cybergate service therefore no longer needs standing permission to read your tenant's domain configuration, and nothing reads it when nobody is signed in to the portal how to update the admin consent updating consent replaces the existing grant with the current, smaller set of permissions it requires a global administrator of your organization sign in to the cybergate management portal as a global administrator go to basic → global and open the 'consent' tab click 'update admin consent' you are redirected to microsoft to grant the access rights review the requested permissions, this is the reduced set listed in 'permissions requested by cybergate' above, and approve them on behalf of your organization you are returned to the cybergate management portal the 'consent' tab now shows 'admin consent has been provided for this tenant' and the warning is gone