To enable integration between Hub and Microsoft services like Outlook and Teams, the Thrive Hub for Outlook application must be approved in your Microsoft Entra (formerly Azure AD) environment.
Application (client) ID:
5bacaeb0-d1f1-4719-95f1-21bd8e57db08Publisher: Thrive Learning
For how to approve the application, see How to Authorise Thrive Hub for Outlook.
How permissions are requested
The application declares the permissions below. Not every permission is requested from every user. Permissions are requested per connection, based on the widget being connected. A user who connects only their calendar is not asked for access to their mail.
This matters when you approve the application:
Approving when a user connects a widget grants only that widget's permissions.
Using the Grant admin consent button in the Microsoft Entra portal grants everything declared below, including permissions for widgets your organisation may not use.
Always requested
These four are requested on every connection, for sign-in and to keep the connection active.
Permission | Purpose | Admin consent |
|---|---|---|
| Sign the user in | No |
| Read basic profile information | No |
| Read the user's email address | No |
| Keep the connection active without asking the user to sign in again | No |
Requested per widget
Widget | Permission | Purpose | Admin consent |
|---|---|---|---|
Outlook Mail |
| Read the user's mail to display it in the widget | No |
Outlook Mail |
| List the user's mail folders, such as Inbox | No |
Outlook Calendar, Teams Calendar |
| List calendars, display events, show availability | No |
Outlook Calendar, Teams Calendar |
| Create and manage calendar entries, used by the Events feature | No |
Teams Messages |
| Read the user's Teams chat messages | No |
Teams Messages |
| Read the user's Teams chat messages | No |
Teams Messages |
| Read the names of teams the user belongs to | No |
Teams Messages |
| Read the names of channels the user belongs to | No |
Teams Messages |
| Read Teams channel messages | Yes |
Teams Messages |
| Read files the user can access | No |
Teams Messages |
| Read items in site collections the user can access | No |
Teams Messages |
| Resolve the display name and profile photo of message authors, so the widget can show who sent each message and identify (and hide) the signed-in user's own messages | No |
Declared but not currently requested
These permissions are declared by the application but are not requested by any current Hub widget. They are listed here so that this page matches exactly what you see in Microsoft Entra if you previously gave admin consent to the Oauth application.
Permission | Admin consent |
|---|---|
| No |
| No |
| No |
| Yes |
| Yes |
| Yes |
| Yes |
Permission Type: Delegated
All permissions listed above are delegated. This means the app acts on behalf of the signed-in user and only accesses data the user is already permitted to see. No application-level (app-only) permissions are required, and there is no tenant-wide background access to all mailboxes.
You can confirm this yourself in Microsoft Entra: go to Enterprise applications, open Thrive Hub for Outlook, select Permissions, and check the Type column. Every entry shows Delegated.
Scoping and Testing
If you wish to test these integrations with a small group of users before a full rollout, you can manage this via your Microsoft environment:
Azure App Assignment: On the Thrive Hub side, widgets cannot currently be restricted to specific groups. However, your IT team can limit access by configuring App Assignment in Azure.
User Experience: With this configuration, all users may see the widget, but only those assigned in Azure will be able to successfully sign in and use it.
Note:
Last checked against the Thrive Hub for Outlook app registration: 17 August 2026.