Hello Atlassian Community,
I am an Atlassian Engineer at Open Source Consulting. Currently, I am working on integrating the Atlassian Rovo Outlook Connector for an enterprise environment, but our client's security team has raised critical concerns and blocked the integration.
I would appreciate any official guidance, documentation, or best practices regarding the following security issues:
1. Violation of the Principle of Least Privilege (PoLP)
The security team pointed out that granting the Mail.Read Application Permission in Microsoft Entra ID provides the app with read access to the entire organization's mailboxes (including sensitive departments like HR, Finance, and C-level). They consider this an excessive scope that violates PoLP.
Question: Does the Rovo Outlook Connector support Delegated Permissions so it only acts on behalf of the logged-in user?
Question: If Application Permission is strictly required by design, does Atlassian officially recommend using Microsoft Exchange's ApplicationAccessPolicy to restrict the app's access to a specific Mail-enabled Security Group?
2. Concerns about Generative AI & Sensitive Data Exposure
The security team is also concerned that because Rovo uses Generative AI, it might index or search beyond what a user would normally query, potentially exposing highly sensitive data that shouldn't be easily surfaced.
Question: How exactly does Rovo inherit and verify the user's M365 permissions during a search?
Question: Could you provide any official architecture documents or security whitepapers detailing how Rovo ensures data isolation and prevents unauthorized data access (No Data Ingestion) during AI processing?
Thank you in advance for your insights. Getting clarification on these specific points will greatly help us coordinate with the strict enterprise security policies.
Best regards,