Security & Trust · Microsoft 365
LodgeHQ and your Microsoft 365 tenancy
Information for the IT administrator or security team deciding whether to allow a LodgeHQ user to connect Outlook, their calendar, OneDrive or SharePoint.
LodgeHQ Pty Ltd · ABN 52 696 192 677 · 12 Rindle Street, Lara VIC 3212, Australia
- Last updated:
- 7 October 2026
- Reviewed against the running system:
- 7 October 2026
- Permanent address:
- https://lodgehq.com.au/security/microsoft-365
In one minute
- Delegated permissions only. LodgeHQ acts as the signed-in user, inside that user’s own consent. It holds no application permissions, no client-credential access and no directory permissions, so it cannot reach any mailbox, calendar or file that the connecting user has not personally authorised.
- Every permission is listed below with what it is used for. Outlook mail is
Mail.ReadandMail.Send; LodgeHQ has never requestedMail.ReadWrite, so it cannot create, alter, move or delete anything in a mailbox. - The mailbox is never modified. Reading is for filing correspondence to client matters; writing is sending only, saved to Sent Items like any other message.
- OneDrive and SharePoint are a one-way copy. LodgeHQ writes matter documents into a folder named LodgeHQ and never downloads or reads the contents of files in your tenancy.
- Verified publisher. The application is published by LodgeHQ Pty Ltd under a Microsoft-verified publisher identity for the domain lodgehq.com.au, so the consent screen shows the verified badge and no unverified-app warning.
- Your tenancy keeps control. Consent can be given per user or once for the organisation, restricted to assigned users, and revoked at any time in Microsoft Entra. Revocation takes effect at the connection’s next token refresh, within the hour.
- Data copied into LodgeHQ stays in Australia. LodgeHQ stores your practice’s records, your clients’ records and your uploaded documents in Australia — on Amazon Web Services infrastructure in the Sydney region (ap-southeast-2) — and AI processing runs on Amazon Bedrock in Australia (Sydney and Melbourne, ap-southeast-4).
1. The application your tenancy will see
LodgeHQ uses one multi-tenant application registration in Microsoft Entra for all four connections. It appears in your tenancy under Enterprise applications once a user has consented to it, or once an administrator has approved it.
- Application name
- LodgeHQ
- Publisher
- LodgeHQ Pty Ltd (ABN 52 696 192 677) — Microsoft verified publisher
- Publisher domain
- lodgehq.com.au
- Application (client) ID
ca52657a-4e92-4746-aa22-9830c53a09d4- Sign-in
- OAuth 2.0 authorization code flow against the Microsoft identity platform (v2.0), multi-tenant. Each connection starts from a signed request bound to the LodgeHQ user who initiated it, and Microsoft returns the user to LodgeHQ only at the registered redirect addresses below.
- Permission type
- Delegated only. No application permissions are declared on the registration, and no part of LodgeHQ uses the client-credentials grant against Microsoft Graph.
- Permissions declared on the registration
- Calendars.ReadWrite, Mail.Read, Mail.Send, Mail.Read.Shared, Mail.Send.Shared, User.Read, offline_access. The OneDrive and SharePoint permissions are requested at connection time only, so they are approved separately and only where a firm uses that feature (section 4).
- Redirect (reply) addresses
https://app.lodgehq.com.au/api/email/connect/outlookhttps://app.lodgehq.com.au/api/calendar/connect/outlookhttps://app.lodgehq.com.au/api/cloud-mirror/onedrive/callbackhttps://app.lodgehq.com.au/api/cloud-mirror/sharepoint/callback
- Microsoft Graph endpoints
https://graph.microsoft.com/v1.0only —/mefor the signed-in user, and/users/{address}only for a shared mailbox the user has explicitly connected.- Also connects
- Google Workspace (Gmail, Calendar, Drive), Dropbox, Zoho and plain IMAP. Each is a separate, optional connection; none is affected by what you approve here.
2. Permissions, one by one
Each table lists exactly what the connection requests, in the words Microsoft prints on the consent screen, and what LodgeHQ does with it. Microsoft defines several of these permissions more broadly than LodgeHQ uses them; the right-hand column is the full extent of the use. Microsoft adds openid, profile and email (sign-in identity) to a mail or calendar grant automatically.
Outlook mailbox
| Permission | Wording on the consent screen | What LodgeHQ does with it |
|---|---|---|
Mail.ReadDelegated | Read user mail | Reads the connected mailbox so correspondence can be filed against the right client matter. Each sync takes the newest 50 messages; Deleted Items and Junk are never read. |
Mail.SendDelegated | Send mail as a user | Sends client correspondence from the agent’s own address. Every message is saved to Sent Items in the mailbox, as if sent from Outlook. |
User.ReadDelegated | Sign in and read user profile | Identifies the account being connected (display name and email address). Nothing else from the profile is read. |
offline_accessDelegated | Maintain access to data you have given it access to | Issues a refresh token, so the connection keeps working without the agent signing in again every hour. |
Mail.Read.SharedDelegated Only when a shared mailbox is connected | Read user and shared mail | Reads a shared mailbox (for example admin@ or info@) that the agent explicitly chooses to connect. |
Mail.Send.SharedDelegated Only when a shared mailbox is connected | Send mail on behalf of others | Sends from that shared mailbox’s address. Exchange still applies the Send As / Send on Behalf rights your tenancy has granted the user. |
Outlook calendar
| Permission | Wording on the consent screen | What LodgeHQ does with it |
|---|---|---|
Calendars.ReadWriteDelegated | Have full access to user calendars | Reads busy and free windows so the online booking page offers only open times, and shows the agent’s own appointments beside their LodgeHQ calendar. Neither is stored. Creates, updates and cancels only the events LodgeHQ itself created: consultations and bookings, and the matter-date and task copies an agent chooses to switch on. |
User.ReadDelegated | Sign in and read user profile | Identifies the account being connected. |
offline_accessDelegated | Maintain access to data you have given it access to | Refresh token for the connection. |
OneDrive (a user’s personal drive)
| Permission | Wording on the consent screen | What LodgeHQ does with it |
|---|---|---|
Files.ReadWriteDelegated | Have full access to user files | Creates a folder named LodgeHQ in the connecting user’s OneDrive and copies the firm’s matter documents into it. Lists top-level folder names so the user can choose where that folder goes. Does not download or read the contents of any file. |
User.ReadDelegated | Sign in and read user profile | Identifies the account being connected. |
openid, emailDelegated | Sign users in · View users’ email address | Sign-in identity for the connection. |
offline_accessDelegated | Maintain access to data you have given it access to | Refresh token for the connection. |
SharePoint document library (a shared team library)
| Permission | Wording on the consent screen | What LodgeHQ does with it |
|---|---|---|
Sites.Read.AllDelegated | Read items in all site collections | Lists site and document-library names so the firm administrator can choose which library receives the LodgeHQ folder. Used for that picker only; LodgeHQ does not read documents or list items in your sites. |
Files.ReadWrite.AllDelegated | Have full access to all files user can access | Creates the LodgeHQ folder tree in the chosen library and uploads matter documents into it. Required because the personal Files.ReadWrite permission cannot write into a shared library. |
User.ReadDelegated | Sign in and read user profile | Identifies the account being connected. |
openid, emailDelegated | Sign users in · View users’ email address | Sign-in identity for the connection. |
offline_accessDelegated | Maintain access to data you have given it access to | Refresh token for the connection. |
Not requested, anywhere in LodgeHQ: Mail.ReadWrite, Mail.Read.All, Files.Read.All (application), Directory.Read.All, User.Read.All, Sites.ReadWrite.All, or any permission ending in /.default.
3. What LodgeHQ reads, stores and writes
Outlook mailbox
- Reads. Every 15 minutes, and when the agent presses Sync, LodgeHQ fetches the newest 50 messages across the mailbox’s folders, excluding Deleted Items and Junk. Older history is imported only when the agent presses “Import older history”.
- Stores. For each message fetched: sender, recipients, subject, body, a short preview, sent time, read state and the names and sizes of attachments. Messages that match a client — by email address, reference, Department of Home Affairs identifiers or name — are filed to that client’s matter. The rest are held as unfiled so the agent can file them; the unfiled copy is removed when the message is deleted or junked in the mailbox. Attachment files themselves are downloaded only when an email is filed to a client matter or lead.
- Writes. Sending only: new messages through
sendMail(saved to Sent Items) and replies throughreply. LodgeHQ does not hold the permission to edit, move, mark as read, delete or create items in the mailbox (Mail.ReadWrite), so it cannot change anything that is already there. - Shared mailboxes. Read or sent only if the agent explicitly connects one, which adds the two
.Sharedpermissions and still depends on the Exchange delegation your tenancy has granted that user.
Outlook calendar
- Reads. Busy and free windows (start, end and show-as status) so the public booking page offers only genuinely open times, and the agent’s own events (title and time) to show beside their LodgeHQ calendar. Neither is stored in LodgeHQ.
- Writes. Creates events for consultations and bookings (with a Teams meeting where the agent chooses one) and, if the agent switches it on, copies of matter dates and tasks. It updates, cancels or deletes only events it created itself.
OneDrive and SharePoint
- Direction. One way, from LodgeHQ into your tenancy. Files placed in the folder by hand are not read back into LodgeHQ.
- Where. A folder named
LodgeHQ, at the root of the drive or inside a folder the firm administrator picks, withClientsandEmployerssub-folders named for each matter. - What is copied. The firm’s own case files: client documents, agent documents, questionnaire PDFs, signed documents, service agreements, generated letters, invoices and deposit requests.
- Reads. Folder names for the destination picker (OneDrive), site and library names for the picker (SharePoint), and the metadata of items LodgeHQ created. It never downloads file contents.
- Changes and deletions. LodgeHQ renames or moves only items it created, and only within its own folders. When a document is removed in LodgeHQ, the copy goes to the drive’s recycle bin. On disconnect it writes a file named “LodgeHQ - SYNC STOPPED.txt” and stops; everything already copied stays in your tenancy, under your control.
4. How the connection and its tokens are protected
- Encrypted at rest. Access and refresh tokens are encrypted with AES-256-GCM by the application before they are written to the database, which is itself encrypted at rest under a customer-managed AWS KMS key in Sydney. The application key is held in AWS Systems Manager Parameter Store as an encrypted secret that only the production service role can read.
- Short-lived access. Microsoft access tokens expire after about an hour and are renewed with the refresh token. If your tenancy revokes consent, disables the user or applies a Conditional Access policy, that renewal fails, LodgeHQ marks the connection as needing reconnection and stops syncing.
- Bound to the user. A connection can be completed only by the LodgeHQ user who started it, in the same browser session; a connection link cannot be handed to someone else.
- Disconnect in LodgeHQ. Deletes the stored tokens and the unfiled mailbox copy. Correspondence already filed to a client matter stays with that matter as the agent’s practice record. Disconnecting does not itself remove the consent record from your tenancy; section 6 covers that.
- Platform controls. Every tenant-scoped read and write is filtered by the firm identifier of the caller in the query itself, so a request for another firm record returns not-found. We will be precise about what that is and is not: it is enforced by each route handler, not by a database-level rule that makes an unscoped query impossible. Route-level scoping was reviewed across the codebase during the July 2026 assessment and no unscoped access path was found.
- Audit. We record sign-ins, administrative actions, document downloads, individual client-record views and data exports — each with the user, the action, the resource, the IP address and the user agent, and never the data values themselves.
5. Approving the connection in your tenancy
How consent is granted depends on your tenancy’s user-consent policy. All of the permissions above are delegated permissions that Microsoft classifies as not requiring administrator consent by default, so in a tenancy that allows users to consent, the agent simply signs in, reviews the list and accepts. Where your policy restricts user consent, the agent sees “Approval required” or “Need admin approval”, and one of the routes below is needed. One approval covers the Outlook mailbox and calendar connections for everyone at that firm; the OneDrive and SharePoint permissions are approved separately, and only if the firm uses them.
Route A — one-click approval link (recommended)
This is Microsoft’s own tenant-wide admin-consent endpoint, pre-filled with LodgeHQ’s application ID. An administrator with the Cloud Application Administrator role or higher opens it, signs in, reviews the permissions and selects Accept; Microsoft then returns them to a LodgeHQ confirmation page. LodgeHQ shows the same link to the agent at the moment their connection is stopped, with a Copy button, so they can send it to you.
- Outlook mailbox and calendar:
https://login.microsoftonline.com/organizations/adminconsent?client_id=ca52657a-4e92-4746-aa22-9830c53a09d4&redirect_uri=https%3A%2F%2Fapp.lodgehq.com.au%2Fapi%2Femail%2Fconnect%2Foutlook&state=lhq_admin_consent - OneDrive:
https://login.microsoftonline.com/organizations/v2.0/adminconsent?client_id=ca52657a-4e92-4746-aa22-9830c53a09d4&redirect_uri=https%3A%2F%2Fapp.lodgehq.com.au%2Fapi%2Femail%2Fconnect%2Foutlook&state=lhq_admin_consent&scope=https%3A%2F%2Fgraph.microsoft.com%2FCalendars.ReadWrite+https%3A%2F%2Fgraph.microsoft.com%2FMail.Read+https%3A%2F%2Fgraph.microsoft.com%2FMail.Send+https%3A%2F%2Fgraph.microsoft.com%2FMail.Read.Shared+https%3A%2F%2Fgraph.microsoft.com%2FMail.Send.Shared+https%3A%2F%2Fgraph.microsoft.com%2FUser.Read+offline_access+openid+email+https%3A%2F%2Fgraph.microsoft.com%2FFiles.ReadWrite - SharePoint:
https://login.microsoftonline.com/organizations/v2.0/adminconsent?client_id=ca52657a-4e92-4746-aa22-9830c53a09d4&redirect_uri=https%3A%2F%2Fapp.lodgehq.com.au%2Fapi%2Femail%2Fconnect%2Foutlook&state=lhq_admin_consent&scope=https%3A%2F%2Fgraph.microsoft.com%2FCalendars.ReadWrite+https%3A%2F%2Fgraph.microsoft.com%2FMail.Read+https%3A%2F%2Fgraph.microsoft.com%2FMail.Send+https%3A%2F%2Fgraph.microsoft.com%2FMail.Read.Shared+https%3A%2F%2Fgraph.microsoft.com%2FMail.Send.Shared+https%3A%2F%2Fgraph.microsoft.com%2FUser.Read+offline_access+openid+email+https%3A%2F%2Fgraph.microsoft.com%2FSites.Read.All+https%3A%2F%2Fgraph.microsoft.com%2FFiles.ReadWrite.All
The links use the organizations tenant selector, so consent is recorded in the home tenancy of the administrator who signs in. Replying “approved” to Microsoft’s notification email does not grant anything.
Route B — Microsoft Entra admin centre
Available once LodgeHQ is listed in your tenancy (after any user has attempted to connect, or after Route A):
- Sign in to the Microsoft Entra admin centre as at least a Cloud Application Administrator.
- Browse to Entra ID › Enterprise apps › All applications and open LodgeHQ.
- Under Security, select Permissions, review the list, then select Grant admin consent.
Route C — admin consent requests
If your tenancy has the admin consent workflow switched on, the agent’s attempt creates a request. Review it under Entra ID › Enterprise apps › Admin consent requests, where you can approve it for that user alone or for the organisation. Requests expire after about 30 days, and the Microsoft notification email is informational only.
Keeping the grant narrow
- Specific users only. Open the LodgeHQ enterprise application, set Assignment required to Yes under Properties, and assign the users or group who may connect. Everyone else is refused at sign-in.
- Per-user instead of tenant-wide. Approve the individual request in Route C, or allow the user to consent for themselves; nothing requires an organisation-wide grant.
- Your policies still apply. Every access is a user sign-in through your tenancy, so Conditional Access, MFA requirements, sign-in risk policies and the Entra sign-in log apply to LodgeHQ exactly as they do to any other application.
- After approval the agent connects again from LodgeHQ. Nothing is connected, and nothing is read, until that second step completes.
6. Revoking access
- Tenant-wide consent: Entra ID › Enterprise apps › LodgeHQ › Permissions › Admin consent tab, then the … control on a permission › Revoke permission.
- Everything at once: delete the LodgeHQ enterprise application from your tenancy. This removes every consent record and blocks sign-in until it is approved again.
- A single user’s own consent: Microsoft exposes these grants through Microsoft Graph or PowerShell (
oauth2PermissionGrants) rather than the admin-centre portal; disabling the user or applying a Conditional Access policy has the same effect on LodgeHQ. - In LodgeHQ: the agent, or a firm administrator, disconnects the mailbox, calendar or drive from the LodgeHQ settings, which deletes the stored tokens.
After a revocation in Entra, LodgeHQ’s next token refresh fails and the connection is marked as needing reconnection; no further reads or sends occur. Documents already mirrored to OneDrive or SharePoint remain in your tenancy, and correspondence already filed to a client matter remains in that matter.
7. Where the copied data goes
LodgeHQ stores your practice’s records, your clients’ records and your uploaded documents in Australia — on Amazon Web Services infrastructure in the Sydney region (ap-southeast-2) — and AI processing runs on Amazon Bedrock in Australia (Sydney and Melbourne, ap-southeast-4).
AI features run on Amazon Bedrock in Australia — the inference profiles in use resolve only to the Sydney (ap-southeast-2) and Melbourne (ap-southeast-4) regions. The model vendor is Anthropic (Claude). Under Bedrock, AWS operates the model deployment accounts: Anthropic does not receive your prompts, your documents or the model output, and the data is not used to train models. That is the position AWS publishes for Bedrock, and it is the basis on which we use it.
Every service that receives any of this data is named, with its legal entity and country, on our Sub-processor Register. The Microsoft entries there describe the connected mailbox, calendar and drive as processed in your own Microsoft 365 tenancy.
Platform controls in brief
- Hosted on Amazon Web Services in Sydney (ap-southeast-2). The production database is a private PostgreSQL instance with no public endpoint, encrypted at rest under a customer-managed KMS key, Multi-AZ, with automated backups and point-in-time recovery over a 14-day window. Documents are held in a private, versioned S3 bucket in Sydney with public access blocked and encryption at rest.
- TLS in transit with HSTS (one year, including subdomains, preload), a Content Security Policy, anti-framing and content-type-sniffing protections on every response.
- Staff passwords of at least 12 characters, hashed with PBKDF2-HMAC-SHA512 at 210,000 iterations and screened against known-breach data; account lockout after repeated failures; time-based one-time-password two-factor authentication that a firm can make mandatory for all its members; sessions that are revoked on password reset and can be set to expire when idle.
- Secrets, including the Microsoft client secret and the token-encryption key, live in AWS Systems Manager Parameter Store under a dedicated KMS key. Deployments use GitHub OIDC with no stored AWS credentials. Dependencies are scanned weekly, and every change is checked by static analysis and secret scanning before merge.
- If we confirm an eligible data breach affecting your firm, we will notify you within 72 hours of that confirmation — not within 72 hours of resolving it. The notice will tell you what data was affected, what we have done in response, and what you need to decide for your own clients. We anchor the commitment to confirmation because every practice carries its own notifiable-breach obligation for the same event, and you should be able to start your own assessment rather than wait for the end of ours. Separately, we handle breaches under the Notifiable Data Breaches scheme in the Privacy Act 1988: we assess a suspected eligible breach promptly and in any case within 30 days of becoming aware of it, and where the scheme requires it we notify the Office of the Australian Information Commissioner.
8. Credentials and independent review
- LodgeHQ Pty Ltd holds SMB1001:2026 Level 3 (Gold), certificate 012630000052696192677Q, issued by CyberCert on 27 July 2026 and current until 28 July 2027. At Bronze, Silver and Gold that scheme certifies a director attestation against a published control set — the certificate is issued on that attestation, so it is not an independent audit.
- LodgeHQ was independently assessed in July 2026 by TAC Security, a Google-authorised CASA lab, as part of Google verification of our restricted Gmail scopes. It returned no critical, high or medium-severity findings.
- The Microsoft integration is published under a verified publisher identity, which Microsoft issues only to an organisation whose Partner Center account has been verified and whose publisher domain is proven by DNS. It attests to who publishes the application, not to the application’s quality; the sections above are what to assess that against.
- LodgeHQ itself is not ISO 27001 or SOC 2 certified. Those certifications belong to Amazon Web Services, which hosts us, and we do not present them as ours.
9. Questions from IT
Email support@lodgehq.com.au with “IT review” in the subject line. Questionnaires and supplier-assessment forms are welcome and are answered in writing. Our security contact is also published at /.well-known/security.txt.
Related pages: Security & Trust, Sub-processor Register, Privacy Policy, Service Levels, Terms. This page prints cleanly; a dated copy can be saved as PDF from your browser.