Managing user and admin consent in Microsoft Entra
Managing user and admin consent in Microsoft Entra (formerly part of Azure Active Directory, or Azure AD) involves controlling permissions for apps and services. This is particularly important when dealing with third-party applications that require permission to access organizational data for integrations.
Here's a step-by-step overview of managing user and admin consent in a Microsoft Entra admin account:
User Consent Settings in Microsoft Entra
You can configure user consent settings through the Microsoft Entra admin center to control who can consent to apps on behalf of themselves and the organization.
Steps to configure user consent settings:
-
Sign into Microsoft Entra Admin Center:
-
- Navigate to Microsoft Entra Admin Center.
- Sign in with your admin credentials.
- Navigate to Consent Settings:
- In the admin center, go to "Applications" and then select "Enterprise Applications" from the left-side menu.
- Select the "Consent and Permissions" option from the sub-menu.
- Configure Consent Settings:
-
- Under the "Consent and Permissions" section, select the option “Allow user consent for apps”.
-
- Click "Save".
Admin Consent Settings in Microsoft Entra
Under the same Consent and Permissions screen;
- Click on "Admin Consent Settings."
- Set the option "Users can request admin consent to apps they are unable to consent to" to "No."
- Click "Save."
The changes may take some time to take effect, ranging from a few minutes to an hour. Once the change has been applied, you can successfully integrate your Microsoft Calendar with Arborgold. After the connection is established, return to the client Admin Center and revert the Admin and User Consent settings to their previous configuration.
Conclusion: There was a change in the Microsoft Authentication and Security settings which has led to the Integration Issue with Microsoft Calendar and Arborgold. Microsoft recommends disabling user consent for apps, prompting many organizations to configure their settings to "Do not allow user consent" and enable "Admin consent requests."
Once the user is authenticated, these settings can be reverted. After the calendar integration is completed successfully, this process will not be needed again.