Skip to main content

Granting Admin Consent for Andsend's Microsoft Integration in Office 365

Andsend and Microsoft Office 365 (aka. Exchange & Outlook) for IT administrators

Written by Kevin Östlin

Many organizations configure their Microsoft Office 365 tenants with security settings that prevent individual users from granting permissions to third-party applications. This is a common and effective security control allowing IT administrators to maintain oversight and control over which integrations are active within the organization.

For Andsend's Microsoft integration to function correctly within such environments, an administrator must grant consent on behalf of the entire organization. This "admin consent" authorizes the application to access the necessary data and perform actions as required by the integration.

Administrators have several methods for granting this consent:

Methods for granting admin consent

1. Via an Admin Consent URL (preferred method)

This method is universally applicable, regardless of whether the Andsend application has been previously added to your tenant. You will need your organization's unique Tenant ID.

Construct the following URL, replacing {TENANT_ID} with your organization's actual tenant ID (quick guide on how to find your tenant id):

https://login.microsoftonline.com/{TENANT_ID}/adminconsent?client_id=edc3b0ac-2a0a-4d13-993a-c8e2299ee85d

Navigate to this URL in your web browser. You will be prompted to log in as an administrator and review the permissions the Andsend application requests before granting consent.

2. Via app settings in Microsoft Entra

If the Andsend application has already been added to your tenant (either by an administrator or a user who initiated the process before stricter consent controls were in place), you can grant admin consent directly within the Microsoft Entra admin center.

  1. Go to the Applications -> Enterprise applications section in the Microsoft Entra admin center.

  2. Search for "Andsend" in the list of applications. If you cannot find "Andsend" in the list it means that the application is not yet installed in your tenant. In that case, please use the preferred method 1 suggested above.

  3. Click on the "Andsend" entry to open its settings.

  4. In the left-hand sidebar, under the "Security" section, click on "Permissions".

  5. Click the button labeled "Grant admin consent for {your organization}".

3. Configure an admin consent workflow in Microsoft Entra

In some cases you may want to allow users to request admin consent for applications on their own. This might also be useful if you are unable to provide admin consent through either of the alternatives 1 or 2 above. It might also simplify similar admin consent situations for other situations in the future.

By following any of these methods, an administrator can successfully grant the necessary permissions for the Andsend Microsoft integration to operate within your organization's Office 365 tenant, ensuring a smooth and secure experience for your users.

Additionally an administrator can restrict consent to a few selected users or groups of users by following the more advanced workflows below.

Methods for restricting granted consent

1. Restrict Andsend access to specific users or groups (extra security)

Granting admin consent authorizes Andsend for your entire organization. If you'd rather only specific people be able to connect, you can require assignment and then choose who is assigned.

Grant admin consent first. Once an app requires assignment, users can no longer consent for themselves — so enabling this before consenting locks everyone out, including the people you assign.

  1. Go to Applications → Enterprise applications and open the Andsend application.

  2. Open Properties and set the assignment requirement to Yes.

  3. Go to Users and groups → Add user/group and add the people or groups who should be able to connect Andsend.

Anyone not assigned is blocked at sign-in and can't connect their mailbox.

Two limits worth knowing:

  • Assigning a group requires Microsoft Entra ID P1 or P2. Assigning individual users works on any plan.

  • Nested groups aren't supported — members of a group inside an assigned group won't get access. Assign each group directly.

If the assignment setting isn't shown on the Properties page, it can be set through PowerShell by setting appRoleAssignmentRequired on the service principal.

2. Grant per-user consent instead of tenant-wide consent (advanced)

If you'd rather not grant tenant-wide consent at all, an administrator can consent on behalf of one named user. There's no portal screen for this — it's done through Microsoft Graph or Graph PowerShell.

You'll need the Privileged Role Administrator, Application Administrator, or Cloud Application Administrator role. It's two steps, and the second is easy to miss:

  1. Create the delegated permission grant for that user — consentType: "Principal" with the user's object ID as principalId, scoped to email offline_access openid profile Mail.ReadWrite Mail.Send User.Read.

  2. Assign the app to the user. Without this they still can't sign in if assignment is required, and Andsend won't appear in their My Apps portal.

Permissions granted this way aren't subject to review or confirmation and take effect immediately. Microsoft's step-by-step: Grant consent on behalf of a single user.

Verify that admin consent has been granted

To verify whether admin consent has been successfully granted for the app, you can go to the Enterprise application section in Microsoft Entra and check the details for the App.

  1. Go to Applications -> Enterprise applications section in the Microsoft Entra admin center.

  2. Search for "Andsend" in the list of applications. If you cannot find "Andsend" in the list it means that the application is not yet installed in your tenant. In that case, please use the preferred method 1 suggested above to grant admin consent for the app.

  3. Click on the "Andsend" entry to open its details.

  4. In the left-hand sidebar, under the "Security" section, click on "Permissions".

  5. Verify that Admin consent has been granted for all the following permissions: email, offline_access, openid, profile, Mail.ReadWrite, Mail.Send, User.Read

Microsoft's version of this documentation

For the original documentation that this Andsend help article has been based on, please refer to Microsoft's own help article for granting admin consent.

Did this answer your question?