Loome Permissions

After you have signed in with your organization’s Microsoft work account email address, a pop-up will appear to request permissions for Loome. Learn about these requested permissions here, and find our steps to request approval as a user, and approve requests as an administrator for Loome below.

What are the Required Permissions?

When you first log into Loome, you will need to provide the following default permission.

If you later enable user and group lookup in your organization, you will need to provide the following other permissions.

Default Permission:

Permission Description
user. Read This is the base requirement to log into Loome.

If user and group lookup is enabled for your organization:

Permission Description
GroupMember.Read.All This is to resolve groups when you search for groups from Entra ID to assign to RBAC.
User.ReadBasic.All/User.Read.All This is to resolve users when you search for users from Entra ID to assign to RBAC.
offline_access This is to query Microsoft Graph using the user token when they lookup a user and/or group. Loome’s internal authentication system needs to maintain the freshness of a Entra ID token, and to do this Loome uses refresh tokens, which requires offline_access.

Steps for Request Approval

Administrator:

  • If you are an Administrator logging into Loome, you can optionally consent on behalf of your organization.
  • If you have been requested by a user for approval, you can find the consent request in Microsoft Entra ID under ‘Enterprise application’.
    • Under ‘Activity’, select ‘Admin consent requests’.
    • Select the pending request to view the URLs, review permissions and provide consent.
    • You can then accept the permissions.

Users

  • If you are not an Administrator, you may have to request approval. (This is dependent on your organization.)
    • If you don’t have to request approval, you can consent to the permissions.
    • If you need to request approval, provide the reason for your request and click Request Approval.
      • Your Administrator can then review and approve the request.
      • After the permissions have been accepted by your Administrator, you can proceed with signup.

Find the steps with images to accept permission requests and request approval here.