Register OAuth apps for your team without touching the shell. Credentials are encrypted at rest and used by every connector that needs them. Re-run this wizard whenever you rotate a secret.
Admin registers one OAuth app per provider. Each employee then authorizes their personal account at /my/connections. Used for mailbox, drive, and repository access.
The Workspace or subscription owner connects once at the tenant level; the whole team rides that one authorization. Huge unlock for SMB teams that don't want to juggle per-seat credentials.