Knowledge base / Employee Directory / How it works
How it works
Employee Directory is a single SharePoint Framework (SPFx) web part. It runs in each user's browser, inside a SharePoint page. Directory data is read and written only through SharePoint and Microsoft Graph in your tenant.
Employee Directory web part
Runs in the user's browser on a SharePoint page, as the signed-in user. Covers the full browser window.
SharePoint Online: your directory site
Hidden lists with the prefix ED_: employees, profiles, departments, change requests, kudos, favourites, notifications, logs and settings, plus a photo library.
Microsoft Graph
Microsoft Entra ID users and managers, profile photos, Teams presence and sending email, all with the user's own delegated permissions.
Key ideas
- Delegated access only. The app always acts as the person using it. It can never read or do more than that person could in Microsoft 365.
- Background work without a server. The scheduled Microsoft Graph sync and the daily reminders run in the browser of an admin who opens the directory. Locks stop two admins from running the same job at once, and logs record every run.
- Schema as code. The app knows exactly which lists and columns it needs. Setup creates them. After an upgrade, the first visit by a site owner checks them and adds anything missing. Existing data is never removed.
- Live updates. Open pages pick up changes made by others (by default every 30 seconds), so a kudos, an approval or a new setting appears without a reload.
- Everything configurable in the app. Admins change settings in the Admin pages, with Save and Discard buttons. Nothing changes until they save.
Microsoft Graph permissions
The package asks for four delegated permissions. A SharePoint or global administrator approves them once, in the SharePoint admin center under Advanced › API access.
| Permission | Used for | If it is not approved |
|---|---|---|
| User.Read.All | Reading users, managers, profile details and photos (sync and live photos) | No sync and no Microsoft 365 photos. The directory still works with people added by hand. |
| Presence.Read.All | Teams status badges | Status badges simply do not appear |
| Mail.Send | Email notifications from the acting person's mailbox | Email is not sent and the person sees a warning. In-app notifications still work. |
| Mail.Send.Shared | Email from a shared mailbox (the person also needs Send As on it) | Falls back to the person's own mailbox, if that is allowed |