Why does my Microsoft work account need admin approval?
Because your organisation's Microsoft 365 (Entra ID) settings block staff from approving new apps themselves. A Microsoft administrator fixes this once — about 5 minutes in the Microsoft Entra admin center — and then your whole team can connect their work Outlook accounts to Sophiie.
Not the IT person? Send this article to whoever manages your organisation's Microsoft admin centre. They complete it once and everyone can connect. Personal Microsoft accounts aren't affected — this only comes up for work or school accounts.
Before you start (for the administrator)
- Sign in to the Microsoft Entra admin center at entra.microsoft.com.
- You need to be a Global Administrator.
Steps
Step 1 — Allow user consent for verified publishers
- In the Microsoft Entra admin center, go to Enterprise applications → Consent and permissions → User consent settings.
- Under User consent for applications, select "Allow user consent for apps from verified publishers, for selected permissions", then click Save at the top of the page.
Step 2 — Classify the required permissions as low impact
- Still under Consent and permissions, switch to the Permission classifications tab. With the Low tab selected, click + Add permissions.
- In the Request API permissions panel, on the Microsoft APIs tab, select Microsoft Graph.
- Under What type of permissions does your application require?, select Delegated permissions (not Application permissions). Tick all the permissions below in this one panel.
- In the search box, type Mail, expand the Mail group, and tick:
- Mail.ReadWrite — Read and write access to user mail - Mail.Send — Send mail as a user
- Clear the search box, type Calendar, expand the Calendars group, and tick:
- Calendars.ReadWrite — Have full access to user calendars
- Before saving, check whether the five base sign-in permissions are already in the Low list — some tenants include them by default, others need them added manually. If any are missing, add them the same way:
- openid — Sign users in - profile — View users' basic profile - email — View users' email address - offline_access — Maintain access to data you have given it access to - User.Read — Sign in and read user profile
- Click Add permissions at the bottom-left of the panel, then confirm the Permission classifications → Low list contains all eight Microsoft Graph permissions: openid, profile, email, offline_access, User.Read, Calendars.ReadWrite, Mail.ReadWrite and Mail.Send.
Step 3 — Retry the connection
- Have the affected person go back to Sophiie and connect their Microsoft work account again — email at Settings → Inquiries → Email, calendar at Settings → Account → Calendar. Microsoft applies the change to future sign-ins only, so they must retry after you save. The consent prompt should now complete without admin approval.
Common Questions
Is this safe? Does it give Sophiie access to everyone's mail?
No. This is Microsoft's recommended, least-privilege setup, and it grants nothing organisation-wide. Each person still consents only for their own mailbox and calendar during their normal sign-in — classifying these permissions as "Low impact" simply tells Microsoft they're safe for users to approve themselves.
It still doesn't work after the admin made the change — what now?
Check four things: the person is signing in with their work account, not a personal Microsoft account; they've cleared their browser cookies for login.microsoftonline.com and tried again; the change was actually saved on the User consent settings page; and it was a fresh sign-in attempt — the change only applies to future sign-ins.
Does this affect personal Microsoft (Outlook.com) accounts?
No. Personal accounts connect without any of this — admin approval only applies to work or school accounts managed by an organisation.
What is Sophiie actually connecting to?
Your work Outlook mailbox (so she can read and reply to enquiry emails — see "How do I connect my Gmail or Outlook email to Sophiie?") and/or your Outlook calendar (so she can book jobs and avoid clashes — see "How do I connect my Google or Outlook calendar to Sophiie?").
Need More Help?
If the connection is still blocked after these steps, ask Sophiie Assistant in your dashboard first — she can guide you through it. Still stuck? Email support@sophiie.ai or call +61 7 5620 4640 with the affected person's email address, your Microsoft tenant domain, and a screenshot of the error.