LexHouse for IT

What LexHouse reads in your Microsoft 365, what it can't, and who grants each part.

Signing in

Sign-in asks only who the person is: their name and email (openid, profile, email). The Word add-in signs in the same way, through LexHouse's own scope, which reads nothing from Microsoft: access_as_user.

Your IT approves this once for your organisation, on Microsoft's own consent page. The link is made for your organisation, so it isn't on this public page.

Ask for your organisation's link

What it reads, and who grants it

What it can't

Where the steps are

  1. 1Approve sign-in: open your organisation's link on Microsoft's consent page (ask for it above).
  2. 2A law firm: your Exchange admin limits mail to the mailboxes you name, and your IT grants SharePoint sites one by one. Your LexHouse contact walks you through both.
  3. 3A company: create LexHouse's mailbox in your tenant and limit LexHouse to it. The person setting LexHouse up sends you a script from their Setup page, and you send back the one line it prints. They then forward or copy to it what LexHouse needs.
  4. 4For the Teams channels they pick, a second script lets LexHouse read those channels' files, one site at a time.

What we keep