Neruna Join the beta

Guides · For admins

Approving Neruna in Microsoft 365.

If Microsoft says “Admin approval required” at sign-in, someone with admin rights has to approve Neruna once for the organisation. It takes two minutes.

Why searching finds nothing

Neruna is registered with Microsoft as an app for all organisations. In your Microsoft Entra it only appears as “Neruna Desktop” under “Enterprise applications” once someone has consented – before that, searching finds neither the name nor the application ID. Approving via the link below creates the app in your organisation and grants the permissions in one step.

Neruna only acts on behalf of the signed-in person (delegated permissions) – never with access of its own to all mailboxes. Data travels directly between the device and Microsoft, not via Neruna's servers.

The app

Name
Neruna Desktop
Application (client) ID
d365c924-b087-40b6-88a7-823a382785fc
Type
Multi-tenant, public client, delegated permissions only

Or directly from Neruna

As an admin, choose “Add account” → “Microsoft 365 / Outlook.com” in Neruna and sign in with the admin account. In Microsoft's consent window, tick “Consent on behalf of your organization”, then “Accept”. You can remove the account afterwards – the approval stays.

Checking and restricting

In the Microsoft Entra admin center, Neruna now appears under “Enterprise applications” – search for “Neruna Desktop” or the application ID. Under “Permissions” you see what was granted and can revoke it there too.

If not everyone should use Neruna: turn on “Assignment required” in the app's properties and add the allowed people under “Users and groups”. Conditional Access policies apply to Neruna like to any other app.

Permissions – and what for

All delegated Microsoft Graph permissions:

Mail.ReadWrite, Mail.Send
Read, organise, delete and send email
Calendars.ReadWrite
Show calendars, create events and answer invitations
Contacts.ReadWrite
Show and edit contacts
Tasks.ReadWrite
Show and edit task lists
MailboxSettings.Read, MailboxSettings.ReadWrite
Read the time zone, switch out-of-office replies on and off
User.Read, openid, email
Name and address of the signed-in person
offline_access
Stay signed in without logging in again every day