Security & Trust · Microsoft 365

LodgeHQ and your Microsoft 365 tenancy

Information for the IT administrator or security team deciding whether to allow a LodgeHQ user to connect Outlook, their calendar, OneDrive or SharePoint.

LodgeHQ Pty Ltd · ABN 52 696 192 677 · 12 Rindle Street, Lara VIC 3212, Australia

Last updated:
7 October 2026
Reviewed against the running system:
7 October 2026
Permanent address:
https://lodgehq.com.au/security/microsoft-365

In one minute

  • Delegated permissions only. LodgeHQ acts as the signed-in user, inside that user’s own consent. It holds no application permissions, no client-credential access and no directory permissions, so it cannot reach any mailbox, calendar or file that the connecting user has not personally authorised.
  • Every permission is listed below with what it is used for. Outlook mail is Mail.Read and Mail.Send; LodgeHQ has never requested Mail.ReadWrite, so it cannot create, alter, move or delete anything in a mailbox.
  • The mailbox is never modified. Reading is for filing correspondence to client matters; writing is sending only, saved to Sent Items like any other message.
  • OneDrive and SharePoint are a one-way copy. LodgeHQ writes matter documents into a folder named LodgeHQ and never downloads or reads the contents of files in your tenancy.
  • Verified publisher. The application is published by LodgeHQ Pty Ltd under a Microsoft-verified publisher identity for the domain lodgehq.com.au, so the consent screen shows the verified badge and no unverified-app warning.
  • Your tenancy keeps control. Consent can be given per user or once for the organisation, restricted to assigned users, and revoked at any time in Microsoft Entra. Revocation takes effect at the connection’s next token refresh, within the hour.
  • Data copied into LodgeHQ stays in Australia. LodgeHQ stores your practice’s records, your clients’ records and your uploaded documents in Australia — on Amazon Web Services infrastructure in the Sydney region (ap-southeast-2) — and AI processing runs on Amazon Bedrock in Australia (Sydney and Melbourne, ap-southeast-4).

1. The application your tenancy will see

LodgeHQ uses one multi-tenant application registration in Microsoft Entra for all four connections. It appears in your tenancy under Enterprise applications once a user has consented to it, or once an administrator has approved it.

Application name
LodgeHQ
Publisher
LodgeHQ Pty Ltd (ABN 52 696 192 677) — Microsoft verified publisher
Publisher domain
lodgehq.com.au
Application (client) ID
ca52657a-4e92-4746-aa22-9830c53a09d4
Sign-in
OAuth 2.0 authorization code flow against the Microsoft identity platform (v2.0), multi-tenant. Each connection starts from a signed request bound to the LodgeHQ user who initiated it, and Microsoft returns the user to LodgeHQ only at the registered redirect addresses below.
Permission type
Delegated only. No application permissions are declared on the registration, and no part of LodgeHQ uses the client-credentials grant against Microsoft Graph.
Permissions declared on the registration
Calendars.ReadWrite, Mail.Read, Mail.Send, Mail.Read.Shared, Mail.Send.Shared, User.Read, offline_access. The OneDrive and SharePoint permissions are requested at connection time only, so they are approved separately and only where a firm uses that feature (section 4).
Redirect (reply) addresses
  • https://app.lodgehq.com.au/api/email/connect/outlook
  • https://app.lodgehq.com.au/api/calendar/connect/outlook
  • https://app.lodgehq.com.au/api/cloud-mirror/onedrive/callback
  • https://app.lodgehq.com.au/api/cloud-mirror/sharepoint/callback
Microsoft Graph endpoints
https://graph.microsoft.com/v1.0 only — /me for the signed-in user, and /users/{address} only for a shared mailbox the user has explicitly connected.
Also connects
Google Workspace (Gmail, Calendar, Drive), Dropbox, Zoho and plain IMAP. Each is a separate, optional connection; none is affected by what you approve here.

2. Permissions, one by one

Each table lists exactly what the connection requests, in the words Microsoft prints on the consent screen, and what LodgeHQ does with it. Microsoft defines several of these permissions more broadly than LodgeHQ uses them; the right-hand column is the full extent of the use. Microsoft adds openid, profile and email (sign-in identity) to a mail or calendar grant automatically.

Outlook mailbox

PermissionWording on the consent screenWhat LodgeHQ does with it
Mail.Read
Delegated
Read user mailReads the connected mailbox so correspondence can be filed against the right client matter. Each sync takes the newest 50 messages; Deleted Items and Junk are never read.
Mail.Send
Delegated
Send mail as a userSends client correspondence from the agent’s own address. Every message is saved to Sent Items in the mailbox, as if sent from Outlook.
User.Read
Delegated
Sign in and read user profileIdentifies the account being connected (display name and email address). Nothing else from the profile is read.
offline_access
Delegated
Maintain access to data you have given it access toIssues a refresh token, so the connection keeps working without the agent signing in again every hour.
Mail.Read.Shared
Delegated
Only when a shared mailbox is connected
Read user and shared mailReads a shared mailbox (for example admin@ or info@) that the agent explicitly chooses to connect.
Mail.Send.Shared
Delegated
Only when a shared mailbox is connected
Send mail on behalf of othersSends from that shared mailbox’s address. Exchange still applies the Send As / Send on Behalf rights your tenancy has granted the user.

Outlook calendar

PermissionWording on the consent screenWhat LodgeHQ does with it
Calendars.ReadWrite
Delegated
Have full access to user calendarsReads busy and free windows so the online booking page offers only open times, and shows the agent’s own appointments beside their LodgeHQ calendar. Neither is stored. Creates, updates and cancels only the events LodgeHQ itself created: consultations and bookings, and the matter-date and task copies an agent chooses to switch on.
User.Read
Delegated
Sign in and read user profileIdentifies the account being connected.
offline_access
Delegated
Maintain access to data you have given it access toRefresh token for the connection.

OneDrive (a user’s personal drive)

PermissionWording on the consent screenWhat LodgeHQ does with it
Files.ReadWrite
Delegated
Have full access to user filesCreates a folder named LodgeHQ in the connecting user’s OneDrive and copies the firm’s matter documents into it. Lists top-level folder names so the user can choose where that folder goes. Does not download or read the contents of any file.
User.Read
Delegated
Sign in and read user profileIdentifies the account being connected.
openid, email
Delegated
Sign users in · View users’ email addressSign-in identity for the connection.
offline_access
Delegated
Maintain access to data you have given it access toRefresh token for the connection.

SharePoint document library (a shared team library)

PermissionWording on the consent screenWhat LodgeHQ does with it
Sites.Read.All
Delegated
Read items in all site collectionsLists site and document-library names so the firm administrator can choose which library receives the LodgeHQ folder. Used for that picker only; LodgeHQ does not read documents or list items in your sites.
Files.ReadWrite.All
Delegated
Have full access to all files user can accessCreates the LodgeHQ folder tree in the chosen library and uploads matter documents into it. Required because the personal Files.ReadWrite permission cannot write into a shared library.
User.Read
Delegated
Sign in and read user profileIdentifies the account being connected.
openid, email
Delegated
Sign users in · View users’ email addressSign-in identity for the connection.
offline_access
Delegated
Maintain access to data you have given it access toRefresh token for the connection.

Not requested, anywhere in LodgeHQ: Mail.ReadWrite, Mail.Read.All, Files.Read.All (application), Directory.Read.All, User.Read.All, Sites.ReadWrite.All, or any permission ending in /.default.

3. What LodgeHQ reads, stores and writes

Outlook mailbox

Outlook calendar

OneDrive and SharePoint

4. How the connection and its tokens are protected

5. Approving the connection in your tenancy

How consent is granted depends on your tenancy’s user-consent policy. All of the permissions above are delegated permissions that Microsoft classifies as not requiring administrator consent by default, so in a tenancy that allows users to consent, the agent simply signs in, reviews the list and accepts. Where your policy restricts user consent, the agent sees “Approval required” or “Need admin approval”, and one of the routes below is needed. One approval covers the Outlook mailbox and calendar connections for everyone at that firm; the OneDrive and SharePoint permissions are approved separately, and only if the firm uses them.

Route A — one-click approval link (recommended)

This is Microsoft’s own tenant-wide admin-consent endpoint, pre-filled with LodgeHQ’s application ID. An administrator with the Cloud Application Administrator role or higher opens it, signs in, reviews the permissions and selects Accept; Microsoft then returns them to a LodgeHQ confirmation page. LodgeHQ shows the same link to the agent at the moment their connection is stopped, with a Copy button, so they can send it to you.

  1. Outlook mailbox and calendar: https://login.microsoftonline.com/organizations/adminconsent?client_id=ca52657a-4e92-4746-aa22-9830c53a09d4&redirect_uri=https%3A%2F%2Fapp.lodgehq.com.au%2Fapi%2Femail%2Fconnect%2Foutlook&state=lhq_admin_consent
  2. OneDrive: https://login.microsoftonline.com/organizations/v2.0/adminconsent?client_id=ca52657a-4e92-4746-aa22-9830c53a09d4&redirect_uri=https%3A%2F%2Fapp.lodgehq.com.au%2Fapi%2Femail%2Fconnect%2Foutlook&state=lhq_admin_consent&scope=https%3A%2F%2Fgraph.microsoft.com%2FCalendars.ReadWrite+https%3A%2F%2Fgraph.microsoft.com%2FMail.Read+https%3A%2F%2Fgraph.microsoft.com%2FMail.Send+https%3A%2F%2Fgraph.microsoft.com%2FMail.Read.Shared+https%3A%2F%2Fgraph.microsoft.com%2FMail.Send.Shared+https%3A%2F%2Fgraph.microsoft.com%2FUser.Read+offline_access+openid+email+https%3A%2F%2Fgraph.microsoft.com%2FFiles.ReadWrite
  3. SharePoint: https://login.microsoftonline.com/organizations/v2.0/adminconsent?client_id=ca52657a-4e92-4746-aa22-9830c53a09d4&redirect_uri=https%3A%2F%2Fapp.lodgehq.com.au%2Fapi%2Femail%2Fconnect%2Foutlook&state=lhq_admin_consent&scope=https%3A%2F%2Fgraph.microsoft.com%2FCalendars.ReadWrite+https%3A%2F%2Fgraph.microsoft.com%2FMail.Read+https%3A%2F%2Fgraph.microsoft.com%2FMail.Send+https%3A%2F%2Fgraph.microsoft.com%2FMail.Read.Shared+https%3A%2F%2Fgraph.microsoft.com%2FMail.Send.Shared+https%3A%2F%2Fgraph.microsoft.com%2FUser.Read+offline_access+openid+email+https%3A%2F%2Fgraph.microsoft.com%2FSites.Read.All+https%3A%2F%2Fgraph.microsoft.com%2FFiles.ReadWrite.All

The links use the organizations tenant selector, so consent is recorded in the home tenancy of the administrator who signs in. Replying “approved” to Microsoft’s notification email does not grant anything.

Route B — Microsoft Entra admin centre

Available once LodgeHQ is listed in your tenancy (after any user has attempted to connect, or after Route A):

  1. Sign in to the Microsoft Entra admin centre as at least a Cloud Application Administrator.
  2. Browse to Entra ID › Enterprise apps › All applications and open LodgeHQ.
  3. Under Security, select Permissions, review the list, then select Grant admin consent.

Route C — admin consent requests

If your tenancy has the admin consent workflow switched on, the agent’s attempt creates a request. Review it under Entra ID › Enterprise apps › Admin consent requests, where you can approve it for that user alone or for the organisation. Requests expire after about 30 days, and the Microsoft notification email is informational only.

Keeping the grant narrow

6. Revoking access

  1. Tenant-wide consent: Entra ID › Enterprise apps › LodgeHQ › Permissions › Admin consent tab, then the … control on a permission › Revoke permission.
  2. Everything at once: delete the LodgeHQ enterprise application from your tenancy. This removes every consent record and blocks sign-in until it is approved again.
  3. A single user’s own consent: Microsoft exposes these grants through Microsoft Graph or PowerShell (oauth2PermissionGrants) rather than the admin-centre portal; disabling the user or applying a Conditional Access policy has the same effect on LodgeHQ.
  4. In LodgeHQ: the agent, or a firm administrator, disconnects the mailbox, calendar or drive from the LodgeHQ settings, which deletes the stored tokens.

After a revocation in Entra, LodgeHQ’s next token refresh fails and the connection is marked as needing reconnection; no further reads or sends occur. Documents already mirrored to OneDrive or SharePoint remain in your tenancy, and correspondence already filed to a client matter remains in that matter.

7. Where the copied data goes

LodgeHQ stores your practice’s records, your clients’ records and your uploaded documents in Australia — on Amazon Web Services infrastructure in the Sydney region (ap-southeast-2) — and AI processing runs on Amazon Bedrock in Australia (Sydney and Melbourne, ap-southeast-4).

AI features run on Amazon Bedrock in Australia — the inference profiles in use resolve only to the Sydney (ap-southeast-2) and Melbourne (ap-southeast-4) regions. The model vendor is Anthropic (Claude). Under Bedrock, AWS operates the model deployment accounts: Anthropic does not receive your prompts, your documents or the model output, and the data is not used to train models. That is the position AWS publishes for Bedrock, and it is the basis on which we use it.

Every service that receives any of this data is named, with its legal entity and country, on our Sub-processor Register. The Microsoft entries there describe the connected mailbox, calendar and drive as processed in your own Microsoft 365 tenancy.

Platform controls in brief

8. Credentials and independent review

9. Questions from IT

Email support@lodgehq.com.au with “IT review” in the subject line. Questionnaires and supplier-assessment forms are welcome and are answered in writing. Our security contact is also published at /.well-known/security.txt.

Related pages: Security & Trust, Sub-processor Register, Privacy Policy, Service Levels, Terms. This page prints cleanly; a dated copy can be saved as PDF from your browser.