Loome Permissions

After you have signed in with your organization’s Microsoft work account email address, a pop-up will appear to request permissions for Loome. Learn about these requested permissions here, and find our steps to request approval as a user, and approve requests as an administrator for Loome below.

What are the Required Permissions?

When you first log into Loome, you will need to provide the following default permission.

If you later enable user and group lookup in your organization, you will need to provide the following other permissions.

Default Permission:

Permission Description
user. Read This is the base requirement to log into Loome.

If user and group lookup is enabled for your organization:

Permission Description
GroupMember.Read.All This is to resolve groups when you search for groups from Entra ID to assign to RBAC.
User.ReadBasic.All/User.Read.All This is to resolve users when you search for users from Entra ID to assign to RBAC.
offline_access This is to query Microsoft Graph using the user token when they lookup a user and/or group. Loome’s internal authentication system needs to maintain the freshness of a Entra ID token, and to do this Loome uses refresh tokens, which requires offline_access.

Steps for Request Approval

Administrator:

  • If you are an Administrator logging into Loome, you will be asked to accept the requested permissions.
  • If you have been requested by a user for approval, you can find the consent request in Microsoft Entra ID under ‘Enterprise application’.
    • Under ‘Activity’, select ‘Admin consent requests’.
    • Select the pending request to view the URLs, review permissions and provide consent.
    • You can then accept the permissions.

Users

  • If you are not an Administrator, you can request approval.
    • Provide the reason for your request and click Request Approval.
    • Your Administrator can then review and approve the request.
    • After the permissions have been accepted by your Administrator, please log out and then log back in to update the login.

Find the steps with images to accept permission requests and request approval here.