This guide outlines the Entra ID setup requirements for CXA/CXI Teams, including admin consent, authorisation, required API permissions, and recommended administrator roles to ensure a smooth deployment process. It also provides guidance on best practices and the level of access needed to complete the configuration successfully.
Akixi Service Account
We recommend creating a dedicated service account for the Akixi CXA service. This provides easy identification of the Akixi service identity in Microsoft logging and separates from any impact of changes to individual person accounts.
The full detail of minimum M365 permissions required and how they used is in this document below.
M365 Permissions required in summary;
· Global admin to grant permissions and register the Akixi Enterprise App (this is a one time operation)
· Akixi service account e.g. “akixiservice@customerdomain.com“
o Assigned admin roles for initial sync and setup of first Akixi monitored user: Teams Communications Administrator + User Administrator + Exchange recipient administrator
o After initial sync and setup of first Akixi monitored user completed: User Administrator + Exchange recipient administrator roles can be removed from the Akixi service account in EntraID, leaving only Teams Communications Administrator permanently assigned for the duration of using the Akixi CXA service