You'll sign in with a Global or Application Administrator account for the client tenant and grant consent for the scopes below. Nothing runs until you connect and audit — and nothing changes in the tenant without your confirmation, ever.
Only requested when you enable a specific automation — e.g. offboarding needs mailbox and licence write access
Every destructive action — regardless of write scope granted — stops for your explicit confirmation before it runs. This is not configurable off in v1.
You'll be redirected to a Microsoft-hosted page to sign in and approve consent.