When connecting a Microsoft 365 Work or School account to Timelier, users may encounter a screen stating
“Need admin approval” or an error code like AADSTS65004 or AADSTS90094.
This guide explains why this happens, details the narrow security scope Timelier requests, and shows IT administrators how to approve access.
Why Admin Approval is Required
In Microsoft Entra ID (formerly Azure Active Directory), the default security policy for commercial and educational tenants disables unverified user consent for third-party cloud apps.
When an employee signs into Timelier using their corporate email domain (e.g., [email protected]), Entra ID halts the OAuth workflow and requests an administrator’s review and approval.
Security Model: Delegated Permissions Only
Timelier follows the Principle of Least Privilege. All Microsoft Graph permissions requested by Timelier are Delegated permissions, not Application permissions:
- No Tenant-Wide Access: Timelier cannot read other employees’ calendars, access mailboxes across your organization, or perform administrative directory tasks.
- Strict User-Context: The integration operates strictly on behalf of the individual user who authorized it. Timelier can only view calendar events that the specific user already has permission to view.
- Read-Only Calendars: Timelier uses read-only calendar access (
Calendars.Read). Timelier never modifies, reschedules, or deletes appointments from the user’s calendar.
Microsoft Graph Permissions Requested
Depending on which features the user selects in Timelier, the following delegated permissions are requested:
| Permission | Type | Required? | Purpose & Scope |
|---|---|---|---|
| Calendars.Read | Delegated | Yes (as event source) | Allows Timelier to read upcoming event start times, summaries, and attendees to trigger scheduled reminders. Read-only. |
| Mail.Send | Delegated | Optional (email channel) | Allows Timelier to send reminder emails to event attendees directly from the user’s Outlook address when the user selects this notification channel. |
| Chat.ReadWrite | Delegated | Optional (Teams channel) | Allows Timelier to deliver reminder alerts directly to attendees via Microsoft Teams chat when selected by the user. |
| offline_access | Delegated | Yes | Allows Timelier background workers to refresh authorization tokens to evaluate reminders when the user is not actively browsing the web app. |
| openid, profile | Delegated | Yes | Used to verify the user’s identity and display their connected account name in the Timelier portal. |
How an Admin Can Grant Consent
Microsoft 365 administrators have two easy ways to grant consent for Timelier:
Option 1: One-Click Tenant Admin Consent (Fastest)
A Global Administrator or Privileged Role Administrator can grant tenant-wide consent in seconds using Microsoft’s standard admin consent endpoint:
Tenant-Wide Consent URL:
https://login.microsoftonline.com/common/adminconsent?client_id=ddb479be-40bc-4f01-944f-42cf63d17a84&redirect_uri=https://app.timelier.com/api/connectmsft
- Click the link above or paste it into a browser where you are signed in as a Microsoft 365 Administrator.
- Sign in with your administrative account credentials.
- Review the requested delegated permissions, check “Consent on behalf of your organization”, and click Accept.
- Once accepted, any user in your tenant can connect their individual calendar to Timelier without receiving further approval prompts.
Option 2: Approve via Microsoft Entra Admin Center
- Sign in to the Microsoft Entra admin center.
- Go to Identity > Applications > Enterprise applications.
- If your tenant uses the Admin consent request workflow, click Admin consent requests under Activity to view and approve pending requests for Timelier.
- Alternatively, under All applications, search for Timelier or Application ID
ddb479be-40bc-4f01-944f-42cf63d17a84. - Click Permissions in the left menu, then click Grant admin consent for [Your Organization].
• Application Name: Timelier
• Application (client) ID:
ddb479be-40bc-4f01-944f-42cf63d17a84• Publisher: Timelier LLC
Alternative: Connect via Outlook ICS Feed (No Admin Approval Needed)
If your organization has a policy restricting third-party OAuth applications, or if you need reminders working immediately while waiting for IT approval, you can connect your calendar using an Internet Calendar (ICS) feed.
Publishing an ICS link shares your calendar events in a standardized read-only format without requiring OAuth or tenant application consent.
Step-by-Step: How to Get Your Outlook ICS Link
- Open a web browser and sign in to Outlook on the Web at outlook.office.com/calendar.
- Click the Settings gear icon in the top right corner.
- In the Settings panel, navigate to Calendar > Shared calendars.
- Scroll down to the Publish a calendar section.
- Under Select a calendar, choose the calendar you wish to sync (usually named Calendar).
- Under Select permissions, select Can view all details (this ensures Timelier receives event titles and attendee information needed to craft reminder messages).
- Click Publish.
- Two links will appear: an HTML link and an ICS link. Click the ICS link and choose Copy link.
- Return to Timelier, navigate to Sources > Add Source > ICS Calendar, and paste the URL.