Why you are here
Somebody at your organisation is trying to connect their work mailbox to Limena and Microsoft has told them an administrator has to approve it first. That is the Entra default rather than anything unusual about Limena: most organisations allow users to consent only to a small set of low impact permissions, and reading your own mail is not in that set.
One administrator approves once, for the organisation. After that every colleague who wants to use Limena connects their own mailbox without seeing this again.
Everything below is here so you can check it before you decide. If you already know what Limena is, skip to approving.
The application
- application_name
- Limena
- publisher
- LIMENA LABS LTDA Microsoft verified publisher. The blue badge appears on the consent screen.
- application_id
- 18e9faee-b701-49fd-88f8-a24695b7e6f2Match this against the app you see in your own tenant. Names can be copied; this cannot.
- publisher_domain
- limena.io
- permission_type
- delegated onlyLimena holds no application permissions, so it can never act on your tenant on its own.
After approval it appears in your tenant under Entra admin center → Enterprise applications, where you can inspect its permissions, restrict who may use it, and remove it entirely.
What approval does
Every permission below is delegated, which means Limena can only ever act as a signed in user, never on its own. That has one consequence worth being precise about:
- Approving connects nobody’s mailbox. It grants Limena no access to anyone’s mail or calendar. Each person still has to sign in and connect their own account, and their grant reaches only their own mailbox.
- It removes the approval prompt, for everyone. After you approve, any user in your Microsoft tenant who also has a Limena account can connect their own mailbox without asking you again. Limena accounts are issued by your own workspace owner, and the section below shows how to restrict this application to a specific group if you would rather hold both ends.
- Nothing is retroactive. A user who disconnects, or whom you remove, stops being reachable immediately.
Permissions requested
These 6 delegated permissions are listed exactly as Microsoft words them on its own consent screen, so you can match this table line for line against what you are about to approve.
- offline_access
- Maintain access to data you have given it access toKeeps a connected mailbox working in the background. Without it, each user would have to sign in again every hour.
- User.Read
- Sign in and read user profileReads the signed in user's name and email address, so the mailbox is attached to the right person in Limena.
- Mail.Send
- Send mail as a userSends email as the user, from their own address, so replies come back to them and their own sending reputation is the one in play.
- Mail.Read
- Read user mailReads the user's mail, so replies to their outreach land on the right contact's record. Limena never modifies, moves, flags or deletes anything in a mailbox.
- Mail.ReadBasic
- Read user basic mailReads message properties without message bodies. This is what the optional people discovery scan uses, so it can see who someone corresponds with without reading what they wrote.
- Calendars.ReadWrite
- Have full access to user calendarsReads free and busy time and writes the meetings Limena books, for users who choose to connect a calendar. It stays dormant for everyone who does not.
Not requested
- No write access to mailboxes. Limena does not request
Mail.ReadWrite. It never modifies, moves, flags or deletes anything, and it creates no drafts in your users’ mailboxes. - No application permissions. Nothing on this list lets Limena reach a mailbox without a specific user having signed in and connected it.
- No directory access. Limena does not read your user list, your groups, or your organisation’s structure.
- Nothing is used to train AI models. Mail content sent to a model is processed for that request only. The AI posture page states which models run and what they are sent.
Approve
You need to be a Global Administrator, Privileged Role Administrator, Application Administrator or Cloud Application Administrator. The button sends you to Microsoft, which will ask you to sign in and show you the same permission list before anything is granted.
You will be returned here once Microsoft confirms it. Nothing is granted until you accept on Microsoft’s own screen.
Limiting access
Approval for the organisation does not have to mean availability to the organisation. If only your sales team should be able to connect a mailbox, restrict the application to a group:
- Entra admin center → Enterprise applications → Limena → Properties, and set Assignment required to Yes.
- Then Users and groups → add the group that may use it. Anyone else is refused by Microsoft at sign in.
- Assign the group directly. Entra does not honour nested groups for this.
Revoking access
- For the organisation: Entra admin center → Enterprise applications → Limena → Properties → Delete. Every token issued to it stops working.
- For one person: they can revoke their own connection at myapps.microsoft.com, or disconnect the mailbox inside Limena.
Data handling
Mail that reaches Limena is stored against the contact it belongs to, isolated per tenant at the database layer, and never used to train models. The detail lives in the rest of this portal: data handling, sub-processors, and the data processing agreement.
Approving by hand
Nothing here requires our button. To grant the same consent by hand, in the Entra admin center:
- Enterprise applications → All applications → search for Limena, and check the application ID above matches.
- Permissions → Grant admin consent for your organisation, then review the same list and accept.
- If the application is not listed yet, it appears the first time one of your users attempts to connect, or as soon as consent is granted through the button above.
Questions before you approve anything are welcome at hello@limena.io.