Module 08 · Privacy and security
For IT administrators
Coming soon
How a Google Workspace or Microsoft 365 administrator allows StellarFirm for Google Drive, OneDrive, and SharePoint, limits who uses it, and removes it.
On this page
People connect Google Drive, OneDrive, and SharePoint to StellarFirm with their own Google or Microsoft sign-in. Many organizations decide which apps may use that sign-in. This page is for the administrator who makes that call: what StellarFirm asks for, what it does with it, and the steps to allow it, limit it, and remove it.
What StellarFirm does with the access#
- Reads the files the signed-in person can already open, when they ask about their files in chat.
- Saves a new file into a folder the person picks, only after the person approves that one file on the Approvals screen. There is no setting that saves without asking.
- Never changes, renames, moves, shares, or deletes a file that is already there, and never changes a site, a folder's sharing, or anyone's permissions. A new file never replaces one with the same name.
- Sees nothing the person cannot see. Every call runs as that person, so your sharing settings, labels, and policies apply.
- Keeps the sign-in stored encrypted in StellarFirm cloud, never shows it back, and deletes it when the person presses Disconnect.
The permissions below read broader than this, because Google and Microsoft offer no narrower permission that lets an app save into a folder a person already has. StellarFirm's own tools are limited to reading and creating new files.
Google Workspace#
What StellarFirm asks for#
| Google shows | Why |
|---|---|
| See, edit, create, and delete all of your Google Drive files | Read the person's files, and save a new file into the folder they pick |
| See your primary Google Account email address | Show which account is connected |
| Associate you with your personal info on Google | Part of every Google sign-in |
Allow StellarFirm#
- Sign in to the Google Admin console as a super administrator, or an administrator with the security settings privilege.
- Go to Security, then Access and data control, then API controls.
- Under App access control, click Manage Third-Party App Access.
- Click Configure new app, search for StellarFirm, and select it. If it does not show yet, ask StellarFirm support for its OAuth client ID and search by that.
- Choose who it applies to: everyone, or one organizational unit or group.
- Choose Trusted. Limited also works, but only while Drive is not set to Restricted (below).
- Click Finish, then ask people to sign in again from the Google Drive page in StellarFirm.
If Drive is restricted for third-party apps#
Under API controls, Manage Google Services, a Drive set to Restricted lets only Trusted apps use it. Marking StellarFirm as Trusted (step 6) is enough; you do not need to open Drive to every app. A Limited app cannot use a restricted service.
If Unconfigured third-party apps is set to block all apps, people see that StellarFirm is blocked until you configure it as above.
Limit or remove it#
- To let only some people use it, configure StellarFirm for that organizational unit or group only, and leave it unconfigured or Blocked for the rest.
- To remove it for everyone, set StellarFirm to Blocked under Manage Third-Party App Access. Every sign-in stops working at once, and the StellarFirm page asks people to connect again.
- A person can remove it themselves under their Google Account, Security, Your connections to third-party apps and services.
- Reporting, Audit and investigation, OAuth log events shows who allowed StellarFirm and when. Files StellarFirm saves show in the Drive log as created by the person who approved them.
Microsoft Entra ID#
What StellarFirm asks for#
| Microsoft shows | Permission | Why |
|---|---|---|
| Sign you in and read your profile | User.Read | Show which account is connected |
| Have full access to all files you have access to | Files.ReadWrite.All | Read the person's files, and save a new file into the folder they pick |
| Read items in all site collections | Sites.Read.All | SharePoint only: find sites and their document libraries. Read only |
| Maintain access to data you have given it access to | offline_access | Keep the connection without asking every hour |
| View your email address, and sign in | email, openid | Part of every Microsoft sign-in |
All of them are delegated permissions: StellarFirm acts as the signed-in person, never as an app with its own access to your tenant.
Why people see "Need admin approval"#
Your tenant decides whether people may approve apps themselves, under Microsoft Entra admin center, Identity, Applications, Enterprise applications, Consent and permissions, User consent settings:
| Setting | What people see |
|---|---|
| Do not allow user consent | Need admin approval, every time |
| Allow user consent for apps from verified publishers, for selected permissions | Need admin approval when a permission is not in the allowed list. Files.ReadWrite.All and Sites.Read.All are rarely in it |
| Allow user consent for apps | They can accept themselves |
Allow StellarFirm for your organization#
Pick one. Each needs a Global Administrator, Privileged Role Administrator, Cloud Application Administrator, or Application Administrator.
- Sign in once yourself. Connect OneDrive or SharePoint in StellarFirm with your administrator account. On Microsoft's permission screen, tick Consent on behalf of your organization, then Accept.
- Use the admin consent link. Ask StellarFirm support for StellarFirm's application ID, then open
https://login.microsoftonline.com/<your tenant ID>/adminconsent?client_id=<application ID>and accept. - Grant it in Entra. Once StellarFirm appears under Enterprise applications, open it, then Permissions, then Grant admin consent for your organization.
Then ask people to sign in again from the OneDrive or SharePoint page in StellarFirm.
Let people ask you instead#
Under Enterprise applications, Consent and permissions, Admin consent settings, turn on Users can request admin consent to apps they are unable to consent to and pick who reviews the requests. People then send a request from the Need admin approval screen, and it waits for you under Enterprise applications, Admin consent requests.
Limit or remove it#
- To let only some people use it, open StellarFirm under Enterprise applications, then Properties, set Assignment required to Yes, and add those people or groups under Users and groups.
- Conditional Access policies apply to StellarFirm sign-ins like any other app.
- To stop it for everyone, set Enabled for users to sign in to No under its Properties, or delete it from Enterprise applications. Every sign-in stops working.
- A person can remove it themselves at myapps.microsoft.com.
- The Entra sign-in logs list each StellarFirm sign-in. Files StellarFirm saves show in the Microsoft 365 audit log as uploaded by the person who approved them.
Questions people ask#
Can StellarFirm read mailboxes, chats, or calendars with this? No. These permissions cover files and SharePoint sites only. Email and calendars connect separately, with their own permissions.
Does every person need to connect? Each StellarFirm account connects its own Google or Microsoft account. Assistants then see what that one account can see.
Can an assistant save without asking? No. Every save waits for the person's Approve, and there is no auto-approve switch for saving files. See Approvals and control.