Email from one mailbox
The app sends email only from a shared mailbox. An attempt to send as another person was refused (HTTP 403).
Microsoft 365 automation with Microsoft Graph means apps in your Azure subscription that read and write Outlook, SharePoint and Teams data with only the permissions a specific job needs.
An automation flow · illustrative example
01
Automation pays off when the same work repeats and there is a clear rule for doing it. Most often it is work that moves between several places:
02
We tested these building blocks in our own test environment with invented data. We put them together into a solution for your process.
The app sends email only from a shared mailbox. An attempt to send as another person was refused (HTTP 403).
Files are moved to the right folder and renamed to the standard, with write access to one SharePoint site only. An existing file is not overwritten.
Scanned PDFs are read with Azure Document Intelligence in your subscription, without a key, using a managed identity.
A reminder with buttons in a Teams chat, and a file sent back in the chat filed in SharePoint.
The app runs in your subscription, in an EU region, with a managed identity. In our test one run took 5.6 to 8.1 seconds.
When Microsoft throttles requests and asks the app to wait, it pauses and carries on later instead of retrying straight away.
03
Power Automate suits many simple flows, and if it is enough, we say so. We suggest a Microsoft Graph app when you need the narrowest permissions, more complex logic, text recognition or a clear log of every action.
If you already have Power Automate flows created in employees' personal accounts, note this: an app can list them only after an administrator registers it as a Power Platform management app. That is a broader right than reading. Without it Microsoft answers HTTP 403; we checked this in our test.
04
For each job we ask for the narrowest permission we have tested.
| Job | Permission | Access |
|---|---|---|
| Send email | Exchange “Application Mail.Send”, scoped to one shared mailbox | Send, one mailbox |
| Read document libraries | Files.Read.All and Sites.Read.All, or Sites.Selected with read | Read |
| Move, rename and upload files | Sites.Selected with write on one site | Write, one site |
| Tell active and disabled accounts apart | User.Read.All | Read |
| Read the text of scanned documents | Azure role “Cognitive Services User” | Read |
| List Power Automate flows | Registration as a Power Platform management app | Administration, broader than read |
Other permissions depend on your process. We list them, with the reason for each, in the proposal, before your administrator approves anything.
Something else on your mind?
Power Automate is Microsoft's tool for building flows, and for simple flows it is often enough. A Microsoft Graph app is code in your Azure subscription: it can have narrower permissions, more complex logic and a clear log. We tell you which route to take after the call.
Microsoft allows that only for an app your administrator registers as a Power Platform management app, which is a broader right than reading. Without that step Microsoft answers HTTP 403; we checked this. The simpler route is for your administrator to export the list of flows from the Power Platform admin centre.
If the system has an API or can export data, a connection can be built. We check what is possible and the access limits before quoting, and if a reliable connection is not possible, we tell you before we start.
No. RPA robots click through screens the way a person would. Our apps connect through Microsoft Graph and system APIs, so they do not depend on screen layouts and run with clear, limited permissions.
In your Azure subscription, in the EU region you choose. Microsoft bills you directly for the Azure resources; our price for the work is separate and excludes VAT.
Rules that are expected to change are kept in configuration, and we show you how to change them. Changes to the logic need development and testing, so we agree who is responsible for them.
Support is agreed separately: watching the logs for errors, updating rules and keeping up with Microsoft changes. If you do not need support, we hand the solution and its documentation over to your IT team.