Skip to main content

Microsoft 365 App Authorizations

Authorize Outermind's Microsoft 365 applications so agents can use the mail, calendar, files, Teams, and other capabilities your organization enables.

Overview

Outermind uses separate Microsoft Entra applications for distinct capabilities. This lets your organization approve only the capabilities it needs. The core application, Outermind - Mail & Calendar, is required for agent mail, calendar, contacts, and directory-based message routing. Other applications are optional and are authorized from their own capability pages.

When an agent needs an application that is not authorized, Outermind removes the affected tools before the execution begins. If the missing authorization prevents a transport-specific task from completing, the execution finishes without attempting a tool call that would fail. Platform Admins receive an in-console alert that identifies the affected agent and links to the authorization page.

Responding to an authorization alert

  1. Select the notification bell in the console header, then open the authorization alert in Support > Messages.
  2. Review the agent name and the Microsoft 365 application named in the alert.
  3. Select Authorize in Settings. The action opens the relevant Microsoft 365 authorization page.
  4. On the authorization card, review the application status and select Authorize in Microsoft 365.
  5. Sign in to Microsoft and approve the requested permissions. This requires a Microsoft 365 Global Administrator or Privileged Role Administrator.
  6. Return to Outermind and select Verify now. The card shows Authorized when Microsoft confirms the grant.

If you do not hold one of the required Microsoft roles, copy the consent link from the card and send it to the administrator who does. After they approve it, return to the card and select Verify now.

Core Permissions

The alert for Outermind - Mail & Calendar opens Administration > Core Permissions (/administration/permissions/core). This required application enables agents to read and send mail, work with calendars and contacts, and perform directory lookups used for message routing.

The page shows a status card for the application:

StatusWhat it meansWhat to do
Not authorizedMicrosoft has not granted the application for your tenant.Select Authorize in Microsoft 365, then select Verify now after approval.
Re-authorization neededOutermind requires permissions that were added after the previous approval.Review the listed changes, re-authorize, then verify.
AuthorizedThe current authorization was verified with Microsoft.No action is needed.
Verification failedOutermind could not confirm the status with Microsoft.Select Verify now again. This does not mean the grant was removed.

Important: A missing Core Permissions grant prevents agents from using mail-based capabilities. Complete the authorization before expecting those workflows to run.

Notification behavior

The authorization alert is sent to active Platform Admins when Outermind first detects that an agent needs an unauthorized application. To avoid repeated notifications while the same issue is being addressed, Outermind limits alerts for the same tenant and application to once per administrator in a 24-hour period.

After the application is authorized, the alert condition clears. If authorization is later revoked, a new alert can be sent when an agent needs the application again.

Frequently asked questions

Does the alert mean an agent execution failed?

Not necessarily. Outermind checks the agent's available tools before execution and excludes tools that depend on the missing application. Most agents can continue with their remaining tools. A transport-specific trigger that cannot work without the missing tool completes cleanly instead of failing at the final tool call.

Why did I receive an alert instead of the person who configured the agent?

Microsoft tenant-wide consent is an administrative action. The alert is sent to Platform Admins so the people able to authorize the application can act directly.

I authorized the application, but the alert is still visible. What should I do?

Open the alert, select Authorize in Settings, and use Verify now on the authorization card. Microsoft consent can take a short time to propagate. If verification continues to fail after a few minutes, refresh the page and try again.

Can I ignore an authorization alert?

Yes, if your organization intentionally does not use the affected capability. Agents will not use tools that require the unauthorized application. Leave the application unauthorized only when that limitation is acceptable for the affected workflows.