Skip to main content

Configuring Admin Consent

Grant admin consent once and every user in your organization can connect ServiceOps to Microsoft email without individual permission prompts.

When integrating ServiceOps with Microsoft services, users may encounter a prompt requiring admin approval. Admin consent grants organization-wide permissions to the ServiceOps application in Azure AD, so individual users do not need to approve access themselves. This is required when your Azure tenant has user consent disabled.

Azure AD controls whether users can consent to applications on their own behalf. When user consent is allowed, a user clicking Sign in with Microsoft in ServiceOps sees a standard permissions acceptance screen and can proceed independently. When user consent is disabled by an administrator, the user instead sees an Approval required screen and must submit a consent request for an Azure Global Administrator to review and approve.

Once an admin grants consent for the organization, all current and future users in the tenant can use the ServiceOps email integration without individual prompts, unless an admin later removes consent.

Step 1: Verify the Enterprise Application Exists

Sign in to the Microsoft Azure portal and navigate to Enterprise Applications > All Applications. Search for ServiceOps-Email-Global-App.

Azure Enterprise Applications list with ServiceOps-Email-Global-App highlighted

If the application is not listed, proceed to Step 3. The user consent request flow will register it.

Step 2: Verify Users and Groups

If the application is listed, click it and navigate to Manage > Users and groups. Confirm the email user is listed and has the Default Access role assigned. If the user is missing, click Add user/group to add them.

ServiceOps-Email-Global-App Users and groups page showing Admin user with Default Access role

If user consent is allowed in your Azure tenant, clicking Sign in with Microsoft in ServiceOps shows the standard permissions acceptance screen below. No further action is needed. Click Accept to proceed.

Microsoft permissions acceptance screen shown when user consent is allowed

If your Azure tenant has user consent disabled, navigate to Enterprise Applications > Consent and permissions > User consent settings. The Do not allow user consent option is selected, which means an administrator must approve all application consent requests.

Azure User consent settings showing Do not allow user consent selected

In this case, when a user attempts to sign in with Microsoft in ServiceOps, the following Approval required screen appears instead of the standard permissions screen.

Microsoft Approval required screen prompting the user to enter a justification and request admin approval

Enter a justification for requesting the application and click Request approval. The request is added to the Admin consent requests queue in Azure.

Azure Enterprise applications Admin consent requests queue showing a pending Motadata ServiceOps request

Step 5: Review the Request Details

The Azure Global Administrator navigates to Enterprise Applications > Admin consent requests and clicks the pending request to view its details.

Admin consent request Details panel showing application name, reply URLs, and Review permissions and consent button

Click Review permissions and consent. The permissions dialog appears listing all access the application is requesting. The admin reviews the permissions and clicks Accept to grant organization-wide consent.

Microsoft Permissions requested dialog for the organization showing IMAP access permissions and the Accept button

Step 7: Verify and Configure

Once consent is granted, the ServiceOps-Email-Global-App appears in Enterprise Applications. Admins can review the granted permissions under the Permissions section and confirm the user is listed under Users and groups.

Azure Enterprise Applications list confirming ServiceOps-Email-Global-App is present after admin consent is granted

The user can now navigate to Admin > Support Channel > Emails in ServiceOps and configure the incoming or outgoing email server using the Sign in with Microsoft option without encountering the approval prompt.