For the first connection only, ShareGate Apricot requires a global administrator or privileged role administrator to consent the app on your tenant. This consent gives ShareGate Apricot authorization to access the resources needed to crawl your environment and the permissions needed for users to be able to use the app.
Note: For the consent to take effect, the tenant requires an active SharePoint Online license.
Why is consent needed?
ShareGate Apricot is a multi-tenant application registered in the ShareGate Azure Active Directory as an Active Directory Application. ShareGate Apricot uses resources from Azure, Microsoft Graph, and SharePoint Online APIs to perform certain actions. Some of the permissions the app requires are delegated permissions, which is why a global admin must consent on behalf of all users in your tenant.
For more information on permissions, see Which permissions does ShareGate Apricot require?
Who can access the app?
Once a global administrator has consented the app, any global admin, SharePoint admin, or groups admin can log in to ShareGate Apricot with their Microsoft 365 account.
For more information, see Managing access to ShareGate Apricot.