Why searching finds nothing
Neruna is registered with Microsoft as an app for all organisations. In your Microsoft Entra it only appears as “Neruna Desktop” under “Enterprise applications” once someone has consented – before that, searching finds neither the name nor the application ID. Approving via the link below creates the app in your organisation and grants the permissions in one step.
Neruna only acts on behalf of the signed-in person (delegated permissions) – never with access of its own to all mailboxes. Data travels directly between the device and Microsoft, not via Neruna's servers.
The app
- Name
- Neruna Desktop
- Application (client) ID
d365c924-b087-40b6-88a7-823a382785fc
- Type
- Multi-tenant, public client, delegated permissions only
Approving with a link
Replace example.com with your organisation's domain (or its tenant ID) and open the link in a browser:
https://login.microsoftonline.com/example.com/adminconsent?client_id=d365c924-b087-40b6-88a7-823a382785fc
Sign in with an account allowed to grant consent – e.g. Global Administrator, Cloud Application Administrator or Application Administrator.
Microsoft shows Neruna's permissions (list below). Confirm with “Accept”.
Microsoft then redirects to an address on your own computer (localhost) and the browser says the page can't be reached. That's fine – the approval has been granted.
Open approval link
Or directly from Neruna
As an admin, choose “Add account” → “Microsoft 365 / Outlook.com” in Neruna and sign in with the admin account. In Microsoft's consent window, tick “Consent on behalf of your organization”, then “Accept”. You can remove the account afterwards – the approval stays.
Checking and restricting
In the Microsoft Entra admin center, Neruna now appears under “Enterprise applications” – search for “Neruna Desktop” or the application ID. Under “Permissions” you see what was granted and can revoke it there too.
If not everyone should use Neruna: turn on “Assignment required” in the app's properties and add the allowed people under “Users and groups”. Conditional Access policies apply to Neruna like to any other app.
Permissions – and what for
All delegated Microsoft Graph permissions:
Mail.ReadWrite, Mail.Send- Read, organise, delete and send email
Calendars.ReadWrite- Show calendars, create events and answer invitations
Contacts.ReadWrite- Show and edit contacts
Tasks.ReadWrite- Show and edit task lists
MailboxSettings.Read, MailboxSettings.ReadWrite- Read the time zone, switch out-of-office replies on and off
User.Read, openid, email- Name and address of the signed-in person
offline_access- Stay signed in without logging in again every day