After you have signed in with your organization’s Microsoft work account email address, a pop-up will appear to request permissions for Loome. Learn about these requested permissions here, and find our steps to request approval as a user, and approve requests as an administrator for Loome below.
When you first log into Loome, you will need to provide the following default permission.
If you later enable user and group lookup in your organization, you will need to provide the following other permissions.
| Permission | Description |
|---|---|
user. Read |
This is the base requirement to log into Loome. |
| Permission | Description |
|---|---|
GroupMember.Read.All |
This is to resolve groups when you search for groups from Entra ID to assign to RBAC. |
User.ReadBasic.All/User.Read.All |
This is to resolve users when you search for users from Entra ID to assign to RBAC. |
offline_access |
This is to query Microsoft Graph using the user token when they lookup a user and/or group. Loome’s internal authentication system needs to maintain the freshness of a Entra ID token, and to do this Loome uses refresh tokens, which requires offline_access. |
Find the steps with images to accept permission requests and request approval here.