ProviderMicrosoft Graph
AccessDelegated read-only
ScopeOne bounded request
RecordDurable data-use receipt
Explicit consent
Mailbox data consent

You choose and authorize every scan boundary.

Signing in and connecting Microsoft 365 are separate from authorizing a scan. Retrieval begins only after the service records your exact source, purpose, processing route, retention schedule, and consent.

What you authorize

One source, one purpose, one recorded request.

Permission scope

  • Provider-hosted authorization for one Microsoft 365 mailboxRequested
    You complete it on Microsoft, not here.

    Limit: Warranty Rescue never receives your password.

  • The folder, date range, item ceiling and attachment permissionRequested
    You choose each value before retrieval begins.
  • Your signed identity, organization and source boundaryGranted
    Recorded with the applicable policy versions as the consent record.
  • A durable data-use receiptGranted
    Records provider lifecycle, processing, retention, revocation and deletion for the request.
Continue securely

Start from your signed Warranty Rescue account.

The source and permission screens show the exact values the service records before you submit the scan request.