For IT admins: approve Elvo in Microsoft 365
How the company's Microsoft 365 admin approves Elvo for the tenant and gives a user access to a shared mailbox.
This page is for the person who administers the company's Microsoft 365 tenant, often an external IT provider. Someone at the company tried to connect a mailbox to Elvo and Microsoft stopped them with Needs admin approval. Three steps fix that, and they take about ten minutes.
1. Approve Elvo for the tenant
Elvo's mailbox connection is a multitenant Microsoft app called Elvo M365 Email Connection,
application ID 2f461a90-c7b4-4098-9018-a7b271a0216a. The tenant's policy only lets a Global
Administrator approve it.
Open this link, sign in with a Global Administrator account in the company's tenant, and click Accept:
The same link, for copying:
https://login.microsoftonline.com/organizations/adminconsent?client_id=2f461a90-c7b4-4098-9018-a7b271a0216a&redirect_uri=https://elvo.is/api/auth/microsoft/admin-consentThe consent screen shows the app name, the publisher and the permissions Elvo asks for: reading and sending mail in the mailboxes the user has access to, reading mailbox settings, and the basic profile. Nothing in SharePoint, OneDrive, Teams or the directory.
The app does not exist in your tenant until this link has been accepted. It does not show up under Enterprise applications in the Microsoft Entra admin center, and searching for it there finds nothing. Accepting the link is what creates it, and it grants consent for every user in the tenant at the same time.
After you accept, Microsoft sends you to elvo.is. You do not need an Elvo account for this step, you can close the page.
2. Give the user access to the shared mailbox
Skip this step if the user is connecting their own mailbox.
For a shared mailbox, the user who connects it in Elvo needs two permissions on that mailbox in Exchange:
- Full Access, so Elvo can read the mail
- Send As, so replies go out from the shared address
In the Exchange admin center: Recipients, Mailboxes, open the shared mailbox, Delegation. Add the user under both Read and manage (Full Access) and Send as. Exchange can take up to an hour to apply the change.
3. Ask the user to try again
The user opens Elvo, goes to Settings → Email, clicks Add account and picks Microsoft. They sign in with their own Microsoft account, not the shared mailbox, and choose the mailbox to connect. Nothing else is needed on your side.
What Elvo gets access to
Elvo asks for delegated Graph permissions only: it can do in a mailbox what the signed-in user can do there, and nothing more. The full list, with the application IDs, is on the Outlook / Microsoft 365 page.
Troubleshooting
The user still gets "Needs admin approval" after I accepted. The consent was given in a different tenant than the one the user's mailbox lives in, or the account used was not a Global Administrator in that tenant. Open the link again and check which account and tenant you sign in with.
I cannot find Elvo under Enterprise applications. The link in step 1 has not been accepted yet. The app only appears there after consent.
The mailbox connected, but replies fail to send. Send As is missing on the shared mailbox. Full Access on its own lets Elvo read the mail but not send from the address. Add Send As under Delegation, wait up to an hour, and have the user reconnect the mailbox.
Do we have to do this for every user? No. The consent in step 1 covers the whole tenant. Only step 2 repeats, per shared mailbox and per user who connects it.