# Azure AD App Setup Guide

## Required Application Permissions

Go to Azure Portal → App registrations → Your App → API permissions

### Add these Application Permissions (NOT Delegated):

1. **Microsoft Graph**
   - `Calendars.Read` - Read calendars in all mailboxes
   - `Calendars.ReadWrite` - Read and write calendars in all mailboxes
   - `User.Read.All` - Read all users' full profiles

### Grant Admin Consent

⚠️ **IMPORTANT:** After adding permissions, click **"Grant admin consent for [Your Organization]"**

Without admin consent, the app will receive 401 Unauthorized errors.

## Verify Permissions

After granting consent, you should see:

- Status: ✅ Granted for [Your Organization]
- Type: Application

## Test Token

Run the app and check the console output for token info:

```bash
bun run start
```

Look for:

```
🔍 Token Info: {
  roles: [ 'Calendars.Read', 'Calendars.ReadWrite', 'User.Read.All' ]
}
```
