Category

Microsoft SSO Approval Required in BoldDesk – Causes and Fix

Updated:

When signing in to BoldDesk using Microsoft Single Sign-On (SSO), some users may encounter an “Approval Required” message from Microsoft. This prompt is generated by Microsoft Entra ID (formerly Azure Active Directory) and is typically associated with application consent policies, permission requirements, or user assignment restrictions configured within the organization’s tenant.

This article explains why the approval request occurs and how Microsoft Entra ID administrators can resolve it.

Why Does the “Approval Required” Prompt Appear?

During Microsoft SSO authentication, BoldDesk requests Microsoft Graph permissions necessary to authenticate users and enable supported Microsoft 365 integrations. Depending on the permissions requested and your organization’s Microsoft Entra ID consent settings, administrator approval may be required before users can access the application.

Microsoft Entra ID may display the “Approval Required” prompt when:

  • User consent is restricted by organizational policy.
  • Administrator consent is required for one or more requested permissions.
  • The application has not yet been approved for the user or tenant.
  • Newly requested permissions have not been consented to.
  • An unintended Microsoft account is selected during authentication.

In some scenarios, the approval prompt may appear because Microsoft automatically signs the user in with a different account than the mailbox or email address being configured in BoldDesk.

Approval_Required_for_SSO_Login.png

Common Causes

The “Approval Required” prompt is usually related to consent and access policies configured in Microsoft Entra ID. However, account selection issues during authentication can also trigger similar behavior.

1. Administrator Consent Required for Permissions

Some Microsoft Graph permissions require administrator approval before users can sign in. If the required permissions have not been granted, Microsoft Entra ID blocks access and displays the approval request.
Examples may include permissions that allow access to organizational resources such as user profile information, Microsoft Teams resources, email functionality, or shared mailbox integrations.

2. Consent Granted to a Limited Scope

Consent may have been granted only to:

  • Specific users
  • A security group
  • An administrator account

Users outside this scope will still see the “Approval Required” prompt.

3. Admin Consent Workflow Is Enabled

If the Admin Consent Workflow feature is enabled in Microsoft Entra ID, users cannot grant consent themselves. Instead, they must submit a request that an administrator reviews and approves before access is granted.

4. Updated Application Permissions

If BoldDesk requests new Microsoft Graph permissions that were not included in a previously approved consent grant, Microsoft Entra ID will require additional administrator approval.
This commonly occurs after application updates that introduce new Microsoft 365 integration capabilities.

5. Incorrect Microsoft Account Selected During Authentication

The “Approval Required” message may appear if the user signs in with a Microsoft account that is different from the account being configured in BoldDesk.
This commonly occurs when:

  • Multiple Microsoft accounts are signed in within the same browser.
  • Microsoft automatically selects a previously authenticated account.
  • The mailbox or email address being added to BoldDesk does not match the account used during the Microsoft sign-in process.

When the wrong account is selected, Microsoft may attempt to authorize a different user or mailbox, which can result in unexpected approval requests, permission errors, or email verification failures.

Resolution

Resolving this issue requires action from a Microsoft Entra ID (Azure AD) administrator to review and adjust application consent settings. The following steps outline how to grant the necessary permissions and restore seamless SSO access for users.

Resolution Step

Action Required from Azure AD Administrator

Contact your Microsoft Entra ID administrator and request them to:

  • Approve the BoldDesk enterprise application
  • Grant consent for all required permissions
  • Ensure consent applies to the correct scope:
    • Tenant-wide (recommended), or
    • Specific groups/users as needed

For more details, refer to Microsoft’s documentation on, Admin Consent Workflow.
On setting up SSO with Azure AD, please refer to this documentation: How to Integrate Single Sign-On (SSO) with BoldDesk.

Frequently Asked Questions

  1. Is “Approval Required” a BoldDesk error?
    No. This prompt is generated by Microsoft Entra ID based on tenant consent policies.

  2. Why do only some users see this prompt?
    Consent may have been granted only to specific users or groups, or policies may differ across users.

  3. Can end users resolve this themselves?
    No. If admin consent is required, only an Azure AD administrator can approve access.

  4. Why did it work before but not now?
    This can occur if:

    • Tenant consent policies were updated
    • The application requested new permissions
  5. Can BoldDesk integrate with Office 365 GCC High for features such as Single Sign-On (SSO) and access to shared mailboxes?
    No. BoldDesk supports Microsoft 365 (commercial tenants) for SSO and email integrations. Office 365 GCC High, being a separate government cloud environment, is not natively supported for SSO or shared mailbox integrations at this time.

Related Articles

  1. Installing and Configuring The Microsoft Entra ID
  2. How to Set Up BoldDesk with Azure AD Single Sign-On (SSO)
Was this article useful?
Like
Dislike
Help us improve this page
Please provide feedback or comments
Comments (0)
Access denied
Access denied
Access denied
Access denied

No articles or sections found
No articles or sections found