ShareGate Apricot requires a Global administrator or Privileged role administrator to consent the app for the first connection only, in order to consent the app on your tenant. This consent gives ShareGate Apricot authorization to access the resources needed to crawl your environment, as well as the permissions needed for the users to be able to use the app .
Note: Once a Global Administrator has consented the app, any Global Administrator, SharePoint Administrator, or Groups Administrator can log in to ShareGate Apricot with their Microsoft 365 account. Learn more.
ShareGate Apricot is a multi-tenant application (used by different customers) that is registered in the ShareGate Azure Active Directory. Some of the permissions the app requires are delegated permissions, so a Global Administrator must consent on behalf of all the users in your tenant.
ShareGate Apricot is registered as an Active Directory Application and uses resources from Azure, Microsoft Graph, as well as SharePoint Online APIs.
More information regarding permissions is available here: Permissions required for ShareGate Apricot.