IMPORTANT: You only need this guide if Microsoft shows the message Need admin approval when you connect SharePoint or Outlook. If you can sign in right away, there is nothing else to do.
Why does this message appear?
Many organizations configure Microsoft 365 so that employees cannot grant external apps access themselves. In that case, an administrator has to approve CASUS once for the whole organization. After that, everyone can connect SharePoint or Outlook in CASUS without any further approval.
CASUS is registered with Microsoft as an app from the verified publisher CASUS Technologies AG.
Which permissions does CASUS request?
All permissions are delegated. CASUS always acts on behalf of the signed-in person and only sees content that this person can already access.
Sign-in (openid, profile, offline_access, User.Read): read your name and email address, and keep you signed in.
SharePoint (Sites.Read.All, Files.Read.All): read sites and files the signed-in person can access. Read-only: CASUS cannot change or delete anything in SharePoint.
Outlook (Mail.Read): read emails in the signed-in person's own mailbox. Read-only: CASUS cannot send, change or delete emails.
CASUS only requests a permission when someone turns on the matching integration. If you only use SharePoint, you don't grant access to your emails.
For users: what to do
1. Contact your Microsoft admin or IT provider
The easiest way is to send them the link to this article and tell them whether you want to use SharePoint, Outlook or both. The section for admins below has everything they need.
2. If Microsoft offers you a request, send it
Depending on your organization's settings, Microsoft shows a field for a justification and a Request approval button. Your request then goes straight to your admin, and you get an email as soon as they have decided.
3. Connect the integration again after approval
Open Integrations in CASUS, turn on SharePoint or Outlook and sign in with your Microsoft account. Reload CASUS once before you do this.
For admins: approve CASUS
To grant the approval, you need one of the following roles in Microsoft Entra: Global Administrator, Privileged Role Administrator, Cloud Application Administrator or Application Administrator. Choose the option that fits your situation.
Option A: Approve a request from your employees
This option applies if the admin consent workflow is enabled in your organization and someone has already sent a request.
Sign in to the Microsoft Entra admin center.
Go to Entra ID > Enterprise apps and select Admin consent requests under Activity.
On the My Pending tab, open the request for CASUS.
Select Review permissions and consent, check the list and click Accept.
Option B: Use an approval link
This option always works, even without a request and without a CASUS account of your own.
Open the matching link and sign in with your admin account:
If you want to approve both, use the third link instead of opening the first two one after the other.
Microsoft shows you CASUS, the verified publisher and exactly the permissions for your selection. Check them and click Accept.
You then see a confirmation page from CASUS. You can close the window.
Option C: CASUS is already listed in your enterprise apps
In the Microsoft Entra admin center, go to Entra ID > Enterprise apps > All applications and search for CASUS.
Under Security, select Permissions.
Click Grant admin consent for "…" (it shows your organization's name) and confirm with Accept.
Note: This button grants all permissions CASUS has registered with Microsoft, which includes SharePoint and read access to emails. If you only want to approve SharePoint or only Outlook, use option A or B.
It still doesn't work after approval
The same message keeps appearing: Reload CASUS and turn the integration on again. Check that your admin approved the right integration. In the enterprise apps, check under CASUS > Properties whether Assignment required? is enabled. If it is, assign the people or groups concerned under Users and groups.
The confirmation page says "Approval not confirmed": Open the link again and complete the approval in the same browser within ten minutes. Also check that your account has one of the roles listed above.
Error message with an AADSTS code: Send us the code and a screenshot via the chat. We'll help you and your admin.
Remove the approval
If your organization wants to revoke CASUS's access, your admin can revoke the permissions or delete the app under CASUS in the enterprise apps. Individual users turn the integrations off in CASUS.






