Microsoft 365 · Outlook & Teams
This guide sets up your Microsoft Outlook calendar and Microsoft Teams so appointments booked through Find Advice appear in your diary automatically, avoid double-bookings, and create a Teams join link every time.
Start with Part 1 — or come here if you have hit “Approval required”
Most Microsoft 365 organisations block staff from connecting outside apps until an administrator approves them. It takes about two minutes and it only ever has to happen once for the whole organisation: one approval on an app called LeadConnector and everyone can connect, including people who join later. Doing it up front means nobody is blocked at all. Part 1 is written for whoever administers your Microsoft 365 (including exactly which permissions to expect), Part 2 is for you.
Find Advice connects through a Microsoft app called LeadConnector (publisher: Leadconnector LLC, a Microsoft-verified publisher). It asks only for calendars the signed-in person can already open themselves. By Microsoft’s defaults none of those permissions actually require an administrator — the block is your own tenant’s user-consent policy, which stops staff consenting to any outside app. An administrator therefore has to approve LeadConnector once.
Worth reading before anything else, because almost every difficulty with this comes from the two being confused.
An administrator approves the LeadConnector app. This is a switch at organisation level. It is done once and it covers everyone, including people who join later.
Each advisor signs in as themselves and clicks Connect (Part 2). That is what actually links a diary. An administrator cannot do this on someone else’s behalf.
Approving does not give the app access to anybody’s calendar
This is the part that surprises people. When an administrator approves LeadConnector, no calendar is connected — not the administrator’s, and not the advisor’s. Every permission in the list is delegated, which means it only ever applies to the person signed in at that moment, and only while they are signed in. Since nobody is connecting a diary during the approval, nothing is granted to anything. The approval removes the wall; the advisor still walks through it themselves. An administrator who approves the app gains no access to staff calendars, and gives none away.
Not sure who the administrator is? Just try
The approval link in Option A is its own test, so nobody has to work this out in advance. Whoever opens it either sees an approval screen headed “Review for your organization” — in which case they can do it themselves, in well under a minute — or they are told they need an administrator, and they simply forward the link on. In a smaller firm the advisor is very often the administrator, so send it to them first. No link can give anyone permissions they do not already hold; it only takes whoever does hold them straight to the right screen.
The one action that unblocks it
Someone holding a consent-granting role has to approve LeadConnector for the calendar permissions specifically. The reliable way is the approval link in Option A. The obvious way — the “Grant admin consent” button in the Entra portal — does not work for this app, and the section below Option A explains why in detail. If your staff are already stuck in an approve-and-still-blocked loop, that button is almost certainly the reason.
A note on the menus. Microsoft is part-way through renaming the left-hand navigation, so depending on which build of the portal you get, the trail below starts at either Entra ID or Identity → Applications. Everything after Enterprise apps is the same either way — both of Microsoft’s own current help articles are written each way.
LeadConnector asks only for delegated permissions, so any one of these roles can grant it:
Enough on its own. Also covers Application Administrator.
Also enough — grants consent for any permission on any API.
Required only to switch the request workflow on (Option C, step 1). Not needed to approve.
Being named a “reviewer” is not a permission
Microsoft is explicit about this: designating someone as a reviewer of consent requests does not give them the rights to approve one. Without one of the roles above they can only view, deny or block the request. If a request has been sitting unapproved, check this first.
The fastest route, and the only one that works before anybody has been blocked. One person with the right role opens one link, reads the permissions, and clicks Accept. From that moment every person in the organisation — including anyone who joins later — can connect their own calendar with no prompt and no request. Nothing to configure in the portal.
Copy the whole address below and replace the highlighted yourcompany.co.nz with your organisation’s Microsoft 365 domain — the part after the @ in your work email. Everything else stays exactly as it is.
https://login.microsoftonline.com/yourcompany.co.nz/v2.0/adminconsent?client_id=ca0e521c-c8fd-4359-ab76-79700699a17c&scope=openid%20profile%20offline_access%20https%3A%2F%2Fgraph.microsoft.com%2FUser.Read%20https%3A%2F%2Fgraph.microsoft.com%2FCalendars.Read%20https%3A%2F%2Fgraph.microsoft.com%2FCalendars.Read.Shared%20https%3A%2F%2Fgraph.microsoft.com%2FCalendars.ReadWrite%20https%3A%2F%2Fgraph.microsoft.com%2FCalendars.ReadWrite.Shared%20https%3A%2F%2Fgraph.microsoft.com%2FMailboxSettings.Read&redirect_uri=https%3A%2F%2Fservices.leadconnectorhq.com%2Fappengine%2Foutlook%2Ffinish_oauth1&state=findadvice
Sign in with an account holding one of the roles above. In a smaller firm that is often the advisor themselves — try it before assuming you need IT.
The screen lists seven permissions, all of them calendar or sign-in — they are set out in full further down this page. Microsoft also states plainly: “this app will get access to the specified resources for all users in your organization. No one else will be prompted to review these permissions.” That sentence is the whole point of this option. Click Accept.
After you click Accept, Microsoft hands you back to LeadConnector, which will most likely show an error or a blank page. That is expected and harmless — the approval was already recorded when you clicked Accept. Do not click Accept a second time.
Go to https://entra.microsoft.com/ → Entra ID → Enterprise apps → All applications, open LeadConnector, then Permissions (under Security) → Admin consent tab. The calendar permissions should be listed there against your name. If that tab is empty, the approval did not save — run the link again.
Two things this does not cover
Microsoft Teams asks for one extra permission that is not in this list, so connecting Teams can prompt once more — approve it the same way. And each person still clicks Connect in their own Find Advice account (Part 2). This approval removes the wall, not the step.
This is the single most important thing on this page, because it is the obvious thing to do and it does not work. If someone has already tried it and staff are still blocked, this is why.
Why that button fails here
LeadConnector asks for its calendar permissions dynamically, at the moment a person connects — they are not in the fixed list attached to the app registration. Microsoft is explicit that the portal “doesn’t know about those dynamic permissions at consent time”, and lists this exact case under “user is still blocked even after admin consents”. So the button consents to a completely different set of permissions — in LeadConnector’s case an email set including read and write access to user mail and send mail as a user — and grants no calendar access at all. Your staff stay blocked, and you have approved something you did not want.
Two consequences worth knowing:
The person tries again, is blocked again, asks again, and the same button is pressed again. Nothing changes, because the permission that is missing is never the one being granted.
Microsoft warns that granting tenant-wide consent “may revoke permissions that have already been granted tenant-wide for that application”. If someone presses it after Option A has been done correctly, it can replace the calendar approval with the email one. If that happens, simply run the Option A link again.
The Option A link avoids all of this by naming the calendar permissions explicitly, so what is approved is exactly what is needed — and nothing else.
No link needed. Useful when the administrator is sitting with the person, or when the advisor is the administrator — which in a smaller firm is common.
The person follows Part 2, Step 1 until Microsoft says “Need admin approval”.
That link is on the block screen itself. Sign in with the administrator account. If the advisor is the administrator, they may simply see the approval screen instead of the block.
On the approval screen, tick “Consent on behalf of your organization” before clicking Accept. This is the step that makes it once-for-everyone instead of once-for-one-person.
Prefer to review each person individually? Turn on Microsoft’s request workflow, then act on each request. Microsoft’s documentation says approving a request “allows all users in your tenant to access the application”, so the end result should be organisation-wide.
Use this as a fallback, not a first choice
Because LeadConnector requests its calendar permissions dynamically, we cannot promise this route captures the calendar set rather than the email set — and it is the slowest path, needing a Global Administrator to switch the workflow on before anyone can even ask. If it is approved and the person is still blocked, that is the dynamic-permission problem described above; use Option A.
Go to Entra ID → Enterprise apps → Consent and permissions → Admin consent settings. Set “Users can request admin consent to apps they are unable to consent to” to Yes, choose who reviews requests, and click Save. It can take up to an hour to take effect.
They attempt the connection, type a short justification on the “Approval required” screen, and click Request approval. Reviewers are emailed.
Go to Entra ID → Enterprise apps → Admin consent requests (under Activity) and open the My Pending tab — actions can only be taken there, not on the “All” tab. Select LeadConnector, click Review permissions and consent, sign in, and click Accept.
They are emailed that it was approved, and go back to Part 2 below. Approval does not complete the connection for them — they still click Connect once more.
If your policy is to grant permissions explicitly rather than through a consent screen, this does exactly the same thing as Option A using Microsoft Graph PowerShell. It records the calendar permissions for all users and touches nothing else. Note Microsoft’s own caution: permissions granted this way take effect immediately and are not subject to a review prompt.
Connect-MgGraph -Scopes "Application.ReadWrite.All","DelegatedPermissionGrant.ReadWrite.All"
# Create the LeadConnector service principal if it is not already in your tenant
$sp = Get-MgServicePrincipal -Filter "appId eq 'ca0e521c-c8fd-4359-ab76-79700699a17c'"
if (-not $sp) { $sp = New-MgServicePrincipal -AppId "ca0e521c-c8fd-4359-ab76-79700699a17c" }
$graph = Get-MgServicePrincipal -Filter "appId eq '00000003-0000-0000-c000-000000000000'"
New-MgOauth2PermissionGrant -ClientId $sp.Id -ConsentType "AllPrincipals" -ResourceId $graph.Id `
-Scope "User.Read Calendars.Read Calendars.Read.Shared Calendars.ReadWrite Calendars.ReadWrite.Shared MailboxSettings.Read offline_access"
AllPrincipals is what makes it apply to everyone, now and in future, rather than one person.Get-MgOauth2PermissionGrant -Filter "clientId eq '$($sp.Id)' and consentType eq 'AllPrincipals'".These are the permissions on the approval screen, with the Microsoft Graph permission behind each one. All are delegated — they apply only to the calendar of the person who signs in, never to the whole organisation, and the app cannot act without them being signed in.
User.Read
Identifies who connected.
Calendars.Read
Reads their diary so Find Advice never offers a time they are already busy.
Calendars.Read.Shared
Same, for a calendar that has been shared with them.
Calendars.ReadWrite
Writes the booking into their diary and updates or cancels it if the client reschedules.
Calendars.ReadWrite.Shared
Same, for shared or delegated calendars — needed where an assistant manages the diary.
MailboxSettings.Read
Reads their time zone and working hours so bookings land at the right local time.
offline_access
Keeps the sync running so they are not asked to sign in again every hour.
There is no mail, file, contact or company-wide access in that list. If you want to limit which staff can use it, leave consent granted and restrict access instead — see the next section.
This exact scenario — GoHighLevel, Outlook, admin consent already granted, staff still blocked — has been answered by Microsoft support. Work down this list in order.
On the app’s Permissions page, open the Admin consent tab. If a reviewer without a consent-granting role handled the request, it may have been denied or left pending rather than approved — and the tab will be empty.
Open LeadConnector → Properties. If Assignment required? is Yes, only assigned people can use it — add them under Users and groups → Add user/group. This is also the correct way to limit the app to a few staff rather than the whole organisation.
Go to Enterprise apps → Consent and permissions → User consent settings. If this is set to Do not allow user consent, the sign-in step can still be refused on a fresh account even after the app itself is approved. Allowing user consent for apps from verified publishers is the usual middle ground — LeadConnector is a verified publisher.
A Conditional Access policy requiring MFA, a compliant or hybrid-joined device, or app-enforced restrictions can block the Microsoft sign-in itself — which looks identical to a consent problem. Have the person open https://mysignins.microsoft.com and look at their recent failed sign-ins for a Conditional Access failure. This is a common cause when it works for existing staff but not for a new starter.
A stale sign-in session can keep showing the old prompt. Sign out of Microsoft in that browser, then start Part 2 again.
Not the administrator? Copy the message below and send it to whoever manages your Microsoft 365. Remember to paste your own domain into the link before you send it.
Hi — we’re connecting our work calendars to our CRM (Find Advice, which connects through a Microsoft app called “LeadConnector”, publisher Leadconnector LLC, a Microsoft-verified publisher). Microsoft blocks staff from connecting it until an administrator approves the app once for the organisation.
The quickest way is this link — open it, sign in with an account that can grant consent, check the permission list, and click Accept:
https://login.microsoftonline.com/yourcompany.co.nz/v2.0/adminconsent?client_id=ca0e521c-c8fd-4359-ab76-79700699a17c&scope=openid%20profile%20offline_access%20https%3A%2F%2Fgraph.microsoft.com%2FUser.Read%20https%3A%2F%2Fgraph.microsoft.com%2FCalendars.Read%20https%3A%2F%2Fgraph.microsoft.com%2FCalendars.Read.Shared%20https%3A%2F%2Fgraph.microsoft.com%2FCalendars.ReadWrite%20https%3A%2F%2Fgraph.microsoft.com%2FCalendars.ReadWrite.Shared%20https%3A%2F%2Fgraph.microsoft.com%2FMailboxSettings.Read&redirect_uri=https%3A%2F%2Fservices.leadconnectorhq.com%2Fappengine%2Foutlook%2Ffinish_oauth1&state=findadvice
Please don’t use the “Grant admin consent” button in Enterprise apps for this one. LeadConnector requests its calendar permissions dynamically, so that button consents to a different, statically-registered set — an email set including read/write mail and send-as — and grants no calendar access at all. Microsoft documents this exact case under “user is still blocked even after admin consents”. If we have already been round the approve-and-still-blocked loop, that is why. The link above names the calendar permissions explicitly, which is what makes it work.
A few notes so it goes smoothly. The domain in the link is deliberate — it records the approval in our directory and not somewhere else, so please don’t swap it for a generic one. It needs Cloud Application Administrator or Privileged Role Administrator; being listed as a consent-request reviewer is not enough on its own. After you click Accept, the page you land on will probably show an error — that’s expected, the approval is already recorded. You can confirm it under Entra ID → Enterprise apps → All applications → LeadConnector → Permissions → Admin consent.
The app asks only for delegated permissions on each person’s own account: User.Read, Calendars.Read, Calendars.Read.Shared, Calendars.ReadWrite, Calendars.ReadWrite.Shared, MailboxSettings.Read and offline_access. No mail read, no send-as, no files, no company-wide access. If the consent screen you see mentions mail at all, please stop and tell us — that would mean the link has been altered.
Two reassurances, since they are the usual questions. Approving does not connect or expose anyone’s calendar — the permissions are delegated, so they only apply to whoever is signed in at the time, and each of us still has to link our own diary afterwards. You gain no access to our calendars by approving, and give none away. And please sign in with an administrator account in our own directory (ending in our domain) rather than your own company login — our domain is in the link so a sign-in from elsewhere is refused rather than approving it in the wrong place.
If you would rather grant it explicitly with Microsoft Graph PowerShell instead of a consent screen, there is a short script on the guide page that creates the same tenant-wide grant for those scopes and nothing else — happy to send it over.
And if anyone is still blocked after approval, the usual causes are “Assignment required” being on (we’d need adding under Users and groups — a group works well so new staff inherit it), user consent set to “Do not allow”, or a Conditional Access policy blocking the sign-in — we can check failed sign-ins at mysignins.microsoft.com if that helps. Thank you!
Once your IT team has approved LeadConnector (Part 1), do the steps below inside your own Find Advice account. Each person connects their own — an administrator cannot do it for you.
In Find Advice, click Settings (the gear icon at the bottom-left).
Open Calendars, then click the Connections tab at the top.
Click + Add New, then Connect next to Outlook Calendar.
Sign in with your Microsoft work account and click Accept. Once your IT team has approved LeadConnector, the “Approval required” screen will not appear.
Go to Settings → My Profile and scroll to Calendar Configuration.
Click edit under Primary Calendar and set it to your Outlook calendar. This is the calendar Find Advice reads to avoid clashes, and writes new bookings into.
Connecting Outlook does not connect Teams — it is a separate step. Do this if you want a Teams join link on every booking. You need a Microsoft Teams work or school account (personal Microsoft accounts are not supported).
In Settings → Calendars → Connections, scroll to the Video Conferencing section.
Click Add New (or Connect) next to Microsoft Teams, sign in with the same Microsoft work account, and approve.
Teams may ask for approval too
Teams can show its own one-time Microsoft approval prompt, even after Outlook was approved. If it is blocked, request it and your IT team approves it exactly the same way as Part 1.
So a Teams link is created automatically for every booking:
Go to Settings → Calendars and click Edit on the calendar people book on.
Open the Meeting Details tab and scroll to the Team Members section.
Select the team member who has Teams connected, set their meeting location to Microsoft Teams, then click Save. A unique Teams link now generates for each new booking and is added to the calendar invite.
A request only unblocks you once an administrator actually approves it — and only someone with a consent-granting role (Cloud Application Administrator or Privileged Role Administrator) can do that. Being listed as a reviewer of consent requests is not enough on its own; a reviewer without the role can view, deny or block a request but cannot approve it. This is the single most common reason a request sits there. The quickest way past it is Option A in Part 1 — the admin opens one link and approves the app directly, without waiting on a request.
The LeadConnector app only appears in your organisation after someone has tried to connect. Attempt the calendar connection once (the “Approval required” screen is expected) — the app now exists under Enterprise apps → All applications and your admin can approve it there. For the request list specifically, it also has to be the My Pending tab: the “All” tab is history only and cannot be actioned.
Three things to check, in order: the app’s Permissions → Admin consent tab actually lists the calendar permissions; Properties → Assignment required? is either No, or you have been added under Users and groups; and you have signed out of Microsoft in that browser and tried again. All three are covered at the end of Part 1.
Teams can ask for an extra permission that was not in the first approval, so Microsoft prompts again. Have your admin approve it exactly the same way as Part 1.
That is normal. Copy the “Send this to your IT team” message in Part 1 and send it to whoever manages your Microsoft 365 — it names the app, the exact menu path, the role needed, and the exact permissions, so they can approve it without a back-and-forth.
That one is not a Microsoft problem — it is a setting on the Find Advice side. Nothing your IT team can do will clear it. Call or email me (details below) and I’ll switch it on.
No. Each person signs in and connects their own calendar — an administrator cannot connect Outlook on your behalf. They can only approve the app so that you are able to.
Microsoft 365 and Exchange Online, plus outlook.com, live.com and hotmail. Not supported: mailboxes on an on-premises Exchange server, and anything created only in desktop Outlook that never syncs to the cloud — those events stay invisible, which can look like a broken connection.
The Microsoft Teams integration only works with a work or school (organisation) Microsoft account, not a personal one. Outlook calendar sync works with your work account too.
Your own calendar — to check your availability and add new bookings — your time zone and working hours, and, for Teams, to create online meeting links. Every permission is delegated, meaning it is scoped to your account and only works while you are signed in. There is no access to mail, files, contacts or anything organisation-wide. The full list, with the Microsoft Graph name behind each one, is in Part 1.