Many organisations let only their Microsoft admins approve new apps. Then connecting Microsoft 365 stops on Microsoft's page, saying an admin must approve the app. Once your Microsoft admin approves Bizomate, people in your organisation can connect without that stop. Send this article to your IT admin.
Who can do this
- In Microsoft: an admin of your organisation's Microsoft 365 who can grant consent to apps — for example a Global Administrator, Privileged Role Administrator or Cloud Application Administrator.
- In Bizomate: to approve while connecting (the first way below), the admin needs to be an Admin or Editor of the workspace. The other two ways need no Bizomate account.
Before you start
Decide which steps your workflows will use. Bizomate asks Microsoft only for what the workspace's steps use, so approve after those steps have been added to the workflows — otherwise a later step may ask for something new, which needs approving again.
Steps
The first way: the admin connects, and approves for everyone.
- The Microsoft admin signs in to Bizomate and opens the workspace.
- Select Connections, then + Add connection, then Microsoft 365.
- In Connection name, type a name — for example Consulace IT admin.
- Select Sign in with Microsoft 365, and sign in with the admin account.
- On Permissions requested, tick Consent on behalf of your organization.
- Select Accept.
The admin is brought back to Connections with "Connection added". Everyone else in the organisation can now connect without asking. If the admin does not want their own account used by workflows, they can then revoke and delete this connection — the approval for the organisation stays.
The second way: approve a request.
- The person connecting selects Sign in with Microsoft 365. If your organisation has turned on admin consent requests, Microsoft offers to send a request — they type why they need it and send it.
- The admin opens the Microsoft Entra admin centre at entra.microsoft.com.
- Go to Enterprise applications, then Admin consent requests.
- Open the request for the app named on the sign-in screen, review its permissions, and approve it.
- The person connecting starts again from + Add connection in Bizomate.
The third way: from the app's page in Microsoft Entra. This works once the app appears in your organisation — after someone has tried to connect.
- In the Microsoft Entra admin centre, go to Enterprise applications, then All applications.
- Search for the app by the name shown on the Microsoft sign-in screen, and open it.
- Select Permissions.
- Select Grant admin consent for your organisation, sign in again if asked, review the list, and select Accept.
What happens next
- People in the organisation can connect Microsoft 365 by signing in and accepting, as in Connect Microsoft 365.
- When someone adds a step that needs a permission nobody has approved yet, the step says Needs permission to … and Microsoft may ask for an admin again when they reconnect.
Good to know
- What Bizomate can ask Microsoft for, in Microsoft's names: openid, profile, email, offline_access, User.Read, User.ReadBasic.All, Mail.ReadWrite, Mail.Send, Calendars.ReadWrite, ChannelMessage.Send, ChatMessage.Send, Chat.ReadBasic, Team.ReadBasic.All, Channel.ReadBasic.All, Channel.Create, ChannelMessage.Read.All, Files.ReadWrite.All, Sites.ReadWrite.All, Tasks.ReadWrite. These are all delegated permissions: Bizomate acts only as the person who connected, and only within what that person can already do.
- A connection asks for only what the workspace's steps use, not the whole list.
- To take the approval back, remove the app's permissions or delete the app under Enterprise applications. Connections in Bizomate then stop working and read Needs reconnecting.
If something goes wrong
| What you see | Why | What to do |
|---|---|---|
| No Consent on behalf of your organization box | The account signing in cannot grant consent for the organisation. | Use an account with one of the admin roles above. |
| Not connected — "The provider declined the connection." | Microsoft refused, usually because approval is still needed. | Approve it one of the ways above, then connect again. |
| The app is not in Enterprise applications | Nobody in the organisation has tried to connect yet. | Use the first way, or have someone try to connect first. |