Open appvitae.ai

Microsoft 365 admin approval

If someone at your company tried to connect their Outlook mailbox or calendar to Vitae and saw “Your Microsoft 365 admin needs to approve Vitae before you can connect”, this page is for you.

Nothing is wrong with their account. Microsoft 365 tenants ship with Secure by Default settings, which stop individual users from approving third-party apps for themselves. An administrator approves Vitae once for the tenant, and everyone can then connect.


Who can approve Vitae?

You need one of these Microsoft Entra roles:

  • Global Administrator
  • Privileged Role Administrator
  • Cloud Application Administrator or Application Administrator (these can grant delegated permissions for the tenant)

How do I approve Vitae?

The person who hit the block can send you a ready-made request from inside Vitae. It contains a direct approval link.

  1. Open the approval link they sent you, signed in with your administrator account.
  2. Microsoft shows the list of permissions Vitae is asking for. It matches the table below.
  3. Review the permissions and click Accept.
  4. Tell the recruiter to go back to Vitae and click I have approval, retry.

If you do not have the link, you can also approve from the Microsoft Entra admin center under Identity > Applications > Enterprise applications, find Vitae, then open Permissions and choose Grant admin consent.

Note: Approval is tenant-wide and one time. Individual recruiters still have to sign in with their own account afterwards, and Vitae only ever acts on the mailboxes and calendars that were explicitly connected.


What exactly is Vitae asking for?

Vitae requests five delegated permissions. Delegated means Vitae acts as the signed-in recruiter, on their own mailbox and calendar, and never as the organization.

PermissionMicrosoft’s wordingWhy Vitae needs it
offline_accessMaintain access to data you have given it access toKeeps the connection alive so recruiters do not have to re-authorize every hour.
User.ReadSign in and read user profileConfirms which Microsoft 365 mailbox was connected.
Mail.ReadRead user mailDetects candidate replies so outreach sequences stop on a reply.
Mail.SendSend mail as a userSends outreach from the recruiter mailbox instead of a shared Vitae address.
Calendars.ReadWriteHave full access to user calendarsReads availability and creates or cancels interview events, including Teams links.

What Vitae does not ask for

  • No application permissions. Every permission above is delegated, so Vitae can only ever reach the mailbox of the recruiter who signed in.
  • No access to other people’s mailboxes or calendars.
  • No directory, file, or Teams-message permissions.

What happens if we approve only some of them?

Microsoft consent is all or nothing per app: an administrator cannot tick a subset the way Google’s consent screen allows. If a permission is missing after approval (for example, an older grant that predates a new permission), Vitae flags the affected mailbox as needing attention on the Senders screen and names the missing permission. Re-approving from the link above resolves it.


Common questions

Does approving Vitae give it access to everyone’s email? No. Approval means “this app is allowed to ask”. Each recruiter still signs in individually, and Vitae only reaches the account that signed in.

Can we revoke this later? Yes. In the Microsoft Entra admin center, open Enterprise applications, find Vitae, and delete the application or revoke its permissions. Recruiters can also disconnect their own mailbox from inside Vitae at any time.

We use conditional access policies. Anything else to configure? Vitae connects through a standard OAuth 2.0 authorization code flow, so conditional access applies as usual. If a policy blocks the sign-in, the recruiter sees a Microsoft error rather than the approval message on this page. Contact support with the AADSTS code shown and we will help you narrow it down.


Still stuck?

Reach out to support with the exact message Microsoft showed, including its AADSTS code. That code tells us whether the block is consent, conditional access, or something else.