How to Approve Microsoft Graph Permissions for Barracuda Cloud Archiving Service

How to Approve Microsoft Graph Permissions for Barracuda Cloud Archiving Service

This article explains how to approve the Microsoft Graph application permissions required for Barracuda Cloud Archiving Service (BCAS) in Microsoft 365. Complete this procedure when configuring a new Exchange Online source or reauthorizing an existing Exchange Online source under Mail Sources > Exchange Online in the BCAS user interface.

A Microsoft Entra administrator must review the requested permissions and grant consent for the organization.

Before You Begin

  • Sign in with a Microsoft Entra account that can grant tenant-wide admin consent, such as a Global Administrator or Privileged Role Administrator.

  • Before verifying consent in the Microsoft Entra admin center, start the BCAS authorization workflow first so that the Barracuda Cloud Archiving Service enterprise application is provisioned under Identity > Applications > Enterprise applications.

  • Be prepared to review and approve application permissions for your entire Microsoft 365 organization.

Required Microsoft Graph Permissions

BCAS requests the following Microsoft Graph application permissions. These application permissions allow BCAS to access the Microsoft 365 data required for Exchange Online email import without relying on an individual user’s delegated session. After an administrator grants consent, BCAS uses the approved application permissions to support Microsoft 365 email import and related user, mailbox, and group lookups.

Permission

Service

Why It Is Required

Permission

Service

Why It Is Required

Calendars.Read

Microsoft Graph

Allows BCAS to list calendars and read calendar events for archived Exchange Online mailbox data.

Contacts.Read

Microsoft Graph

Allows BCAS to list contact folders and read contact items in Exchange Online mailboxes.

Exchange.ManageAsApp

Microsoft Graph

Allows BCAS to run Exchange Online PowerShell cmdlets as an application to identify delegated mailboxes.

Group.Read.All

Microsoft Graph

Allows BCAS to enumerate distribution lists and resolve their members for scoped imports and mailbox discovery.

Mail.Read

Microsoft Graph

Allows BCAS to read mail folders, messages, and sticky notes in Exchange Online mailboxes for import.

MailboxFolder.Read.All

Microsoft Graph

Allows BCAS to use the beta Microsoft Graph Exchange admin API to discover well-known PIM folders, including Contacts, Notes, and Tasks.

Tasks.Read.All

Microsoft Graph

Allows BCAS to list Microsoft To Do task lists and tasks associated with Exchange Online mailbox data.

User.Read.All

Microsoft Graph

Allows BCAS to enumerate users and mailboxes in the tenant for mailbox discovery and import configuration.

The Microsoft Graph permissions listed in this article support Exchange Online email import. Shared Mailbox Sync requires additional Exchange Online authorization. For those requirements, see How to Grant Exchange Online Permissions for Shared Mailbox Sync.

Approve the Permissions

Important: Admin consent applies to the entire Microsoft 365 organization. Review each requested permission carefully before granting consent. You do not need to create an application or manually add permissions; BCAS requests the permissions required for supported features.

Use the BCAS setup workflow to grant consent for the Microsoft Graph application permissions requested by BCAS when configuring a new Exchange Online source or reauthorizing an existing Exchange Online source.

Complete Authorization in BCAS

Set up a new Exchange Online email import or reauthorize an existing Exchange Online source. Follow the instructions in How to Configure Microsoft Exchange Online Email Import. During Microsoft authorization, review the requested permissions, select Consent on behalf of your organization, and select Accept. After authorization is complete, you are redirected to BCAS.

Verify Consent in the Microsoft Entra Admin Center

Use the Microsoft Entra admin center to confirm that admin consent has already been granted for the Barracuda Cloud Archiving Service application.

  1. Sign in to the Microsoft Entra admin center.

  2. Go to Identity > Applications > Enterprise applications.

  3. Search for and select the Barracuda Cloud Archiving Service application.

  4. Open the application’s Permissions page.

  5. Review the permissions list and confirm that each required permission displays a status such as Granted for <your organization>. The exact status text may vary in the Microsoft Entra admin center.

If the BCAS setup workflow includes a Microsoft consent prompt, you can also verify that the prompt completes successfully and returns you to the BCAS interface without an approval error.

Troubleshooting Tips

  • Grant admin consent is unavailable – Sign in with a Microsoft Entra role that can grant tenant-wide consent, such as Global Administrator or Privileged Role Administrator.

  • The Barracuda Cloud Archiving Service application does not appear – Confirm that you started the BCAS setup or authorization workflow first in the BCAS user interface so the enterprise application is provisioned in Microsoft Entra ID.

  • Permissions show as not granted – Refresh the page, sign out and back in if necessary, and confirm that the approval process completed successfully.

  • Shared Mailbox Sync still does not work – Confirm that you also completed the Exchange Online permission assignment in How to Grant Exchange Online Permissions for Shared Mailbox Sync.

Known Limitations

The following Exchange Integration features are not supported when using Microsoft Graph API permissions. These limitations are imposed by Microsoft.

Feature

Details

Feature

Details

Archive mailbox import

Importing mail from In-Place Archive (Online Archive) mailboxes is not supported. Microsoft Graph does not provide an API to discover or read In-Place Archive mailboxes.

Distribution list sync

Syncing personal distribution lists (Outlook Contact Groups) from Contacts folders is not supported.

Notes from user-created folders

Syncing sticky notes from user-created subfolders under the Notes folder is not supported. Microsoft Graph does not provide a way to discover user-created note subfolders.

Related Articles


We value your feedback.
If you have questions, suggestions, or feedback on our documentation, contact the Campus Product Documentation team.
For general product inquiries or technical support, please contact the global Barracuda Support team.