Skip to main content

How to Fix "Need Admin Approval" Errors on a Previously Working Microsoft 365 Connection

Resolve sudden "Need admin approval" errors on Outlook, OneDrive, or SharePoint connections that previously worked, by reviewing pending admin consent requests in Microsoft Entra.

How to Fix "Need Admin Approval" Errors on a Previously Working Microsoft 365 Connection

If your organization's Outlook, OneDrive, or SharePoint integrations suddenly stop working — even though nothing was changed on your end, and even though other Microsoft integrations like Teams are unaffected — this guide will help you get reconnected quickly.

You might need this guide when:

  • Outlook, OneDrive, or SharePoint connections that used to work now show a "Need admin approval" popup when users try to authenticate.

  • Your IT team has confirmed your Microsoft Entra (Azure AD) permissions and admin consent look correctly configured, but users still can't connect.

  • The issue appeared suddenly, without your organization making any changes to its Microsoft 365 setup or elvex configuration.

  • The issue is affecting all users in your organization, not just one person.

This is a different scenario from setting up Microsoft 365 integrations for the first time. If you're configuring Outlook, OneDrive, or SharePoint for the first time, start with Configuring Microsoft Entra for elvex Microsoft 365 Integration Actions instead. This guide will show you how to resolve the specific case where a previously working connection abruptly requires re-approval.

Before you begin

  • You'll need access to a Microsoft Entra admin center account with permission to review and approve admin consent requests (typically a Global Administrator, Application Administrator, or Cloud Application Administrator).

  • Confirm with your users that the issue is happening across your organization and not isolated to a single account. If only one user is affected, see the single-user troubleshooting steps in Configuring Microsoft Entra for elvex Microsoft 365 Integration Actions instead, as the cause is likely different.

Why this happens

Based on cases we've seen, this typically happens when the admin consent previously granted for the elvex enterprise application in your Microsoft Entra tenant needs to be re-approved. In at least one confirmed case, this occurred almost exactly 12 months after the organization first connected elvex to Microsoft 365, which suggests it may be tied to a periodic re-consent requirement on Microsoft's side. Microsoft Entra does not always notify your IT team by email when this happens, so your organization may not receive any advance warning before users start seeing approval errors.

The good news: once an admin reviews and approves the pending request, the fix applies tenant-wide. Other users won't need to submit their own individual requests or take any action — they'll simply be able to connect once the admin approval is complete.

Steps

  1. Go to the Microsoft Entra admin center and sign in with an account that can review admin consent requests.

  2. Click Enterprise Apps to view your organization's connected applications.

  3. Click Admin Consent Requests to see any pending requests waiting for approval.

  4. Find elvex in the list and click it to open the request.

  5. Click Review Permissions & Consent — even if it looks like this has already been clicked or actioned before, click it again to be sure the request is fully processed.

  6. Approve the request to grant consent for the elvex application.

  7. Go back to elvex and try reconnecting Outlook, OneDrive, or SharePoint. The connection should now succeed.

📘 Note: If you don't see elvex under Admin Consent Requests, confirm you're looking at the right tenant, and check Enterprise Apps → elvex → Permissions instead — the request may show up there depending on how your admin consent workflow is configured. See Configuring Microsoft Entra for elvex Microsoft 365 Integration Actions for the full permissions review path.

Verifying the fix worked for everyone

Once one admin-approved user can connect successfully, have a second user in your organization try connecting as well, without submitting their own consent request. If they're able to connect right away, the tenant-wide fix is working as expected and no further action is needed from other users.

Common questions

Why did this break Outlook, OneDrive, and SharePoint but not Teams?

Teams is set up as a separate application registration from the Outlook, OneDrive, and SharePoint integrations, which are powered by the Microsoft Graph API through a shared elvex enterprise application. Updating or reinstalling the Teams app doesn't affect the consent status of the other Microsoft 365 integrations, so it's unlikely to be the cause even if the timing looks suspicious.

Do we need to do anything special to prevent this from happening again?

There's currently no confirmed way to prevent a future re-consent requirement, since Microsoft doesn't publish a formal, guaranteed schedule for this. If your organization wants a heads-up before this becomes a problem again, ask your Microsoft Entra admin to enable the Admin Consent Workflow (see Step 5 of Configuring Microsoft Entra for elvex Microsoft 365 Integration Actions) and add themselves as a reviewer, so they receive email notifications when a new admin consent request comes in rather than finding out from affected users.

Do all of our users need to individually request and receive admin approval?

No. Admin consent for the elvex application applies to your whole Microsoft Entra tenant. Once one admin approves the request, all other users in your organization should be able to connect without submitting their own request.

We checked our permissions and they looked correct — why didn't that fix it?

Permissions being correctly configured (Steps 1–6 in Configuring Microsoft Entra for elvex Microsoft 365 Integration Actions) doesn't necessarily mean the current admin consent grant is still active. A pending re-consent request is a different state than a permissions misconfiguration, which is why this guide has you check Admin Consent Requests specifically rather than repeating the initial setup steps.

What's next?

Once your Microsoft 365 integrations are reconnected, you may want to:

Did this answer your question?