# For IT administrators

> How a Google Workspace or Microsoft 365 administrator allows StellarFirm for Google Drive, OneDrive, and SharePoint, limits who uses it, and removes it.

Status: Coming soon

People connect Google Drive, OneDrive, and SharePoint to StellarFirm with their own Google or Microsoft sign-in. Many organizations decide which apps may use that sign-in. This page is for the administrator who makes that call: what StellarFirm asks for, what it does with it, and the steps to allow it, limit it, and remove it.

> [!SOON]
> Google Drive, OneDrive, and SharePoint are Coming soon. This page describes how they will work.

## What StellarFirm does with the access

- **Reads** the files the signed-in person can already open, when they ask about their files in chat.
- **Saves a new file** into a folder the person picks, only after the person approves that one file on the Approvals screen. There is no setting that saves without asking.
- **Never** changes, renames, moves, shares, or deletes a file that is already there, and never changes a site, a folder's sharing, or anyone's permissions. A new file never replaces one with the same name.
- Sees nothing the person cannot see. Every call runs as that person, so your sharing settings, labels, and policies apply.
- Keeps the sign-in stored encrypted in StellarFirm cloud, never shows it back, and deletes it when the person presses **Disconnect**.

The permissions below read broader than this, because Google and Microsoft offer no narrower permission that lets an app save into a folder a person already has. StellarFirm's own tools are limited to reading and creating new files.

## Google Workspace

### What StellarFirm asks for

| Google shows | Why |
| --- | --- |
| See, edit, create, and delete all of your Google Drive files | Read the person's files, and save a new file into the folder they pick |
| See your primary Google Account email address | Show which account is connected |
| Associate you with your personal info on Google | Part of every Google sign-in |

### Allow StellarFirm

1. Sign in to the [Google Admin console](https://admin.google.com) as a super administrator, or an administrator with the security settings privilege.
2. Go to **Security**, then **Access and data control**, then **API controls**.
3. Under **App access control**, click **Manage Third-Party App Access**.
4. Click **Configure new app**, search for **StellarFirm**, and select it. If it does not show yet, ask StellarFirm support for its OAuth client ID and search by that.
5. Choose who it applies to: everyone, or one organizational unit or group.
6. Choose **Trusted**. **Limited** also works, but only while Drive is not set to Restricted (below).
7. Click **Finish**, then ask people to sign in again from the Google Drive page in StellarFirm.

### If Drive is restricted for third-party apps

Under **API controls**, **Manage Google Services**, a Drive set to **Restricted** lets only Trusted apps use it. Marking StellarFirm as Trusted (step 6) is enough; you do not need to open Drive to every app. A Limited app cannot use a restricted service.

If **Unconfigured third-party apps** is set to block all apps, people see that StellarFirm is blocked until you configure it as above.

### Limit or remove it

- To let only some people use it, configure StellarFirm for that organizational unit or group only, and leave it unconfigured or **Blocked** for the rest.
- To remove it for everyone, set StellarFirm to **Blocked** under **Manage Third-Party App Access**. Every sign-in stops working at once, and the StellarFirm page asks people to connect again.
- A person can remove it themselves under their Google Account, **Security**, **Your connections to third-party apps and services**.
- **Reporting**, **Audit and investigation**, **OAuth log events** shows who allowed StellarFirm and when. Files StellarFirm saves show in the Drive log as created by the person who approved them.

## Microsoft Entra ID

### What StellarFirm asks for

| Microsoft shows | Permission | Why |
| --- | --- | --- |
| Sign you in and read your profile | User.Read | Show which account is connected |
| Have full access to all files you have access to | Files.ReadWrite.All | Read the person's files, and save a new file into the folder they pick |
| Read items in all site collections | Sites.Read.All | SharePoint only: find sites and their document libraries. Read only |
| Maintain access to data you have given it access to | offline_access | Keep the connection without asking every hour |
| View your email address, and sign in | email, openid | Part of every Microsoft sign-in |

All of them are delegated permissions: StellarFirm acts as the signed-in person, never as an app with its own access to your tenant.

### Why people see "Need admin approval"

Your tenant decides whether people may approve apps themselves, under **Microsoft Entra admin center**, **Identity**, **Applications**, **Enterprise applications**, **Consent and permissions**, **User consent settings**:

| Setting | What people see |
| --- | --- |
| Do not allow user consent | Need admin approval, every time |
| Allow user consent for apps from verified publishers, for selected permissions | Need admin approval when a permission is not in the allowed list. Files.ReadWrite.All and Sites.Read.All are rarely in it |
| Allow user consent for apps | They can accept themselves |

### Allow StellarFirm for your organization

Pick one. Each needs a Global Administrator, Privileged Role Administrator, Cloud Application Administrator, or Application Administrator.

- **Sign in once yourself.** Connect OneDrive or SharePoint in StellarFirm with your administrator account. On Microsoft's permission screen, tick **Consent on behalf of your organization**, then **Accept**.
- **Use the admin consent link.** Ask StellarFirm support for StellarFirm's application ID, then open `https://login.microsoftonline.com/<your tenant ID>/adminconsent?client_id=<application ID>` and accept.
- **Grant it in Entra.** Once StellarFirm appears under **Enterprise applications**, open it, then **Permissions**, then **Grant admin consent for** your organization.

Then ask people to sign in again from the OneDrive or SharePoint page in StellarFirm.

### Let people ask you instead

Under **Enterprise applications**, **Consent and permissions**, **Admin consent settings**, turn on **Users can request admin consent to apps they are unable to consent to** and pick who reviews the requests. People then send a request from the **Need admin approval** screen, and it waits for you under **Enterprise applications**, **Admin consent requests**.

### Limit or remove it

- To let only some people use it, open StellarFirm under **Enterprise applications**, then **Properties**, set **Assignment required** to **Yes**, and add those people or groups under **Users and groups**.
- Conditional Access policies apply to StellarFirm sign-ins like any other app.
- To stop it for everyone, set **Enabled for users to sign in** to **No** under its **Properties**, or delete it from **Enterprise applications**. Every sign-in stops working.
- A person can remove it themselves at **myapps.microsoft.com**.
- The Entra sign-in logs list each StellarFirm sign-in. Files StellarFirm saves show in the Microsoft 365 audit log as uploaded by the person who approved them.

## Questions people ask

**Can StellarFirm read mailboxes, chats, or calendars with this?** No. These permissions cover files and SharePoint sites only. Email and calendars connect separately, with their own permissions.

**Does every person need to connect?** Each StellarFirm account connects its own Google or Microsoft account. Assistants then see what that one account can see.

**Can an assistant save without asking?** No. Every save waits for the person's Approve, and there is no auto-approve switch for saving files. See [Approvals and control](/docs/trust/approvals-and-control).

---

Source: https://stellarfirm.ai/docs/trust/it-administrators
