The current list of default permissions is here. Basically the app can read and send the user's emails, and access Sharepoint and Teams. How my package currently works is that it obtains an OAuth ...
At the bottom of this tab is a Windows Azure Active Directory section with an App Url predefined for the AMS. This value should be copied and used to complete both Sign-On Url and App Id Uri ...