Overe separates two things that are easy to confuse:
Connecting your tenant. This means granting consent to the Overe enterprise application in Microsoft Entra ID. It needs a privileged Microsoft role, and it happens once.
Using the Overe portal. This is reviewing findings, applying policies and responding to alerts. It needs an Overe role, not a Microsoft admin role.
Our recommended practice is to keep these apart. The people who work in Overe every day should sign in with ordinary, unprivileged Microsoft accounts. A Global Administrator or Privileged Role Administrator should only be involved at the moment of consent.
Why this matters
Many organisations, and their auditors, treat a standing Global Administrator assignment as excessive privilege. Overe doesn't need one to operate.
Overe connects to your tenant through a service principal, which is an enterprise application that holds the specific Microsoft Graph permissions and directory roles you consent to. It doesn't connect through the account of the person who installed it. Once consent is granted, Overe's access comes from the application alone. The administrator who granted consent can leave the Overe portal, and Overe will keep working normally.
For the full list of permissions and roles the application holds, see Understanding Overe Microsoft 365 App Permissions.
Recommended setup
1. Create the Overe account with the person who will manage the service
Sign up to Overe using the Microsoft identity of the person who will run Overe day to day. This account doesn't need any Microsoft 365 or Entra ID administrative role. Within Overe, it will be the Owner of your organisation.
2. Connect the tenant using a privileged administrator
When you add your tenant, the consent step must be completed by someone who holds one of these roles:
Privileged Role Administrator (recommended). This is the least-privileged role that can consent to the Microsoft Graph application permissions Overe requests and assign the Exchange Administrator and Teams Administrator roles to the Overe application.
Global Administrator. This role also works, and it's fine to use if it's the only privileged role available in your tenant.
You can send the consent link to that administrator; they don't need an Overe account. If your organisation uses Privileged Identity Management (PIM), the administrator can activate the role just in time for the consent step and let it expire afterwards.
Application Administrator and Cloud Application Administrator can't complete this step, because they can't consent to Graph application permissions or assign directory roles to an application.
3. Use Overe day to day with unprivileged accounts
Invite your team into the Overe portal and give each person the Overe role that matches their responsibilities:
Owner: full control, including offboarding the organisation and managing other Owners.
Admin: full control, except offboarding and managing Owners.
Viewer: read-only access.
None of these Overe roles require a Microsoft admin role. We recommend having at least two Owners so you're never locked out of your organisation. See Admin Roles and Permissions for details.
Already installed with a Global Administrator?
If a Global Administrator created your Overe account and connected the tenant, you can move to this model without reinstalling:
Invite the person or people who will manage Overe day to day.
Make at least one of them an Owner.
Sign in as the new Owner and remove the Global Administrator from the Overe portal.
The connection to your tenant, including scans, policy controls, monitoring and automated response, continues to work as long as the Overe enterprise application and its granted permissions remain in place in Entra ID.
When you'll need a privileged administrator again
A Privileged Role Administrator or Global Administrator only needs to be involved again if:
Overe asks for additional permissions. When new capabilities are released, you may be asked to re-consent. See Giving consent to missing Microsoft permissions.
A directory role is removed from the Overe application. If someone removes the Exchange Administrator or Teams Administrator role in Entra ID, those roles must be reassigned.
Offboarding doesn't need a privileged administrator. An Overe Owner can offboard from the console, and Overe removes its own application from your tenant.
