Aristo setup & permissions

🌱 We're counting your seats right now. Aristo is working out how many Copilot licences you're paying for — and how many nobody has switched on yet. It takes a minute or two, and this page fills in the moment it lands.
  1. 1Grant admin consent — one click, scoped & read-only
  2. 2Choose your rollout — a pilot cohort or the whole org
  3. 3Aristo takes it from here — warm daily wins, opt-out always honored

Here's exactly what Aristo asks for in your tenant — in plain words — before you connect a thing. Least-privilege, read-only where it can be, aggregate always. Sign in as a Microsoft 365 admin and Aristo checks what's already granted, then fixes any gap in one click.

What Aristo will ask for, and why

read-only
Read aggregate Copilot usage
To see which teams are active vs idle — counts only, whole teams of 5+ (never a per-person trail). (Reports.Read.All · read-only)
read-only
Read your directory (names, roles, teams)
To match each person the right 20-second Copilot win for their role. (User.Read.All · read-only)
one gentle hello
Say a gentle hello in Teams
So Aristo can offer one opt-out nudge — never more than your daily cap. (Teams message · as the app)
only on your tap
Act only on your tap (on-behalf-of you)
A draft or reply happens as YOU, only when you press the button — Aristo never acts on its own. (On-behalf-of · least-privilege)
Sign in to run setup →
No commitment — this only checks your tenant and shows you the picture. Our full trust & data-handling →