Areza
Microsoft 365 automation

We connect Outlook, SharePoint and Teams to your business systems

Microsoft 365 automation with Microsoft Graph means apps in your Azure subscription that read and write Outlook, SharePoint and Teams data with only the permissions a specific job needs.

An automation flow · illustrative example

  1. OutlookEmail received
  2. AzureRules and text recognitionExceptions go to a person
  3. SharePointItem in a list
  4. TeamsMessage to the team

01

When automation is worth it

Automation pays off when the same work repeats and there is a clear rule for doing it. Most often it is work that moves between several places:

  • incoming files are sorted and renamed by hand;
  • reminders and requests are written by hand every week or month;
  • data is retyped from Outlook or SharePoint into a business system, or the other way round;
  • a report is pieced together from several libraries or lists.

02

What we have already tested with Microsoft Graph

We tested these building blocks in our own test environment with invented data. We put them together into a solution for your process.

Email from one mailbox

The app sends email only from a shared mailbox. An attempt to send as another person was refused (HTTP 403).

Moving and renaming files

Files are moved to the right folder and renamed to the standard, with write access to one SharePoint site only. An existing file is not overwritten.

Text recognition

Scanned PDFs are read with Azure Document Intelligence in your subscription, without a key, using a managed identity.

Teams cards and files

A reminder with buttons in a Teams chat, and a file sent back in the chat filed in SharePoint.

An Azure Functions app

The app runs in your subscription, in an EU region, with a managed identity. In our test one run took 5.6 to 8.1 seconds.

Throttling

When Microsoft throttles requests and asks the app to wait, it pauses and carries on later instead of retrying straight away.

03

Microsoft Graph or Power Automate?

Power Automate suits many simple flows, and if it is enough, we say so. We suggest a Microsoft Graph app when you need the narrowest permissions, more complex logic, text recognition or a clear log of every action.

If you already have Power Automate flows created in employees' personal accounts, note this: an app can list them only after an administrator registers it as a Power Platform management app. That is a broader right than reading. Without it Microsoft answers HTTP 403; we checked this in our test.

04

Permissions by job

For each job we ask for the narrowest permission we have tested.

Automation
JobPermissionAccess
Send emailExchange “Application Mail.Send”, scoped to one shared mailboxSend, one mailbox
Read document librariesFiles.Read.All and Sites.Read.All, or Sites.Selected with readRead
Move, rename and upload filesSites.Selected with write on one siteWrite, one site
Tell active and disabled accounts apartUser.Read.AllRead
Read the text of scanned documentsAzure role “Cognitive Services User”Read
List Power Automate flowsRegistration as a Power Platform management appAdministration, broader than read

Other permissions depend on your process. We list them, with the reason for each, in the proposal, before your administrator approves anything.

05

We start with one process

How we work

Together we describe one process: where the data comes from, who makes the decisions and where the result needs to end up. After a 30-minute call we send a fixed pilot price in writing, excluding VAT.

Common questions.

Something else on your mind?

Book a call
How is this different from Power Automate?

Power Automate is Microsoft's tool for building flows, and for simple flows it is often enough. A Microsoft Graph app is code in your Azure subscription: it can have narrower permissions, more complex logic and a clear log. We tell you which route to take after the call.

Can you find Power Automate flows created in personal accounts?

Microsoft allows that only for an app your administrator registers as a Power Platform management app, which is a broader right than reading. Without that step Microsoft answers HTTP 403; we checked this. The simpler route is for your administrator to export the list of flows from the Power Platform admin centre.

Can you connect Microsoft 365 to our business system?

If the system has an API or can export data, a connection can be built. We check what is possible and the access limits before quoting, and if a reliable connection is not possible, we tell you before we start.

Is this RPA?

No. RPA robots click through screens the way a person would. Our apps connect through Microsoft Graph and system APIs, so they do not depend on screen layouts and run with clear, limited permissions.

Where does the app run, and who pays for it?

In your Azure subscription, in the EU region you choose. Microsoft bills you directly for the Azure resources; our price for the work is separate and excludes VAT.

Can we change the rules ourselves?

Rules that are expected to change are kept in configuration, and we show you how to change them. Changes to the logic need development and testing, so we agree who is responsible for them.

Who looks after the solution after launch?

Support is agreed separately: watching the logs for errors, updating rules and keeping up with Microsoft changes. If you do not need support, we hand the solution and its documentation over to your IT team.

Let's agree where to start

In a 30-minute call we find out where your documents are kept, which permissions would be needed and whether to start with a read-only check or a pilot. You are welcome to bring your IT administrator.

Book a free call

30 min · free · price in writing, excluding VAT

A free 30-minute call

After the call we send a fixed price for the check or the pilot in writing, excluding VAT.

  • Where your documents are kept and which permissions would be needed
  • Where to start: a read-only check or a pilot
  • What your IT team would need to do

1 of 2 · How can we reach you?

It takes less than a minute.