Microsoft 365 · Outlook & Teams
This guide sets up your Microsoft Outlook calendar and Microsoft Teams so appointments booked through Find Advice appear in your diary automatically, avoid double-bookings, and create a Teams join link every time.
Seeing “Approval required” or “Need admin approval”?
That message is normal — most Microsoft 365 organisations block staff from connecting outside apps until an administrator approves them. It takes an administrator about two minutes: one approval on an app called LeadConnector, then you connect. Part 1 is written for them (including exactly which permissions to expect), Part 2 is for you.
Find Advice connects through a Microsoft app called LeadConnector (publisher: Leadconnector LLC, a Microsoft-verified publisher). It only asks for the signed-in person’s own calendar. By Microsoft’s defaults none of those permissions actually require an administrator — the block is your own tenant’s user-consent policy, which stops staff consenting to any outside app. An administrator therefore has to approve LeadConnector once.
The one action that unblocks it
Someone holding a consent-granting role has to click Grant admin consent on the LeadConnector app (Option A), or open the pending request and select Review permissions and consent (Option B). Turning on the request workflow, adding reviewers, or assigning users does not approve anything by itself — that is the step most often missed.
LeadConnector asks only for delegated permissions, so any one of these roles can grant it:
Enough on its own. Also covers Application Administrator.
Also enough — grants consent for any permission on any API.
Required only to switch the request workflow on (Option B, step 1). Not needed to approve.
Being named a “reviewer” is not a permission
Microsoft is explicit about this: designating someone as a reviewer of consent requests does not give them the rights to approve one. Without one of the roles above they can only view, deny or block the request. If a request has been sitting unapproved, check this first.
One approval, done. Everyone in the organisation can then connect their own calendar without another prompt.
The LeadConnector app only appears in your tenant after someone has attempted the connection. Seeing the “Approval required” screen is enough — the app now exists in your directory.
Go to https://entra.microsoft.com/ and sign in with one of the roles above.
Go to Entra ID → Enterprise apps → All applications, search for LeadConnector, and select it.
Select Permissions (under Security), review the list, then click Grant admin consent for <your organisation>. Sign in when prompted and click Accept.
Stay on the Permissions page and open the Admin consent tab. The calendar permissions should now be listed there, against your name. If that tab is empty, the consent did not save — try again.
Prefer to review each person individually? Turn on Microsoft’s request workflow, then act on each request. Note the end result is the same: approving a request grants consent on behalf of the organisation.
Go to Entra ID → Enterprise apps → Consent and permissions → Admin consent settings. Set “Users can request admin consent to apps they are unable to consent to” to Yes, choose who reviews requests, and click Save. It can take up to an hour to take effect.
They attempt the connection, type a short justification on the “Approval required” screen, and click Request approval. Reviewers are emailed.
Go to Entra ID → Enterprise apps → Admin consent requests (under Activity) and open the My Pending tab — actions can only be taken there, not on the “All” tab. Select LeadConnector, click Review permissions and consent, sign in, and click Accept.
They are emailed that it was approved, and go back to Part 2 below. Approval does not complete the connection for them — they still click Connect once more.
These are the permissions on the approval screen, with the Microsoft Graph permission behind each one. All are delegated — they apply only to the calendar of the person who signs in, never to the whole organisation, and the app cannot act without them being signed in.
User.Read
Identifies who connected.
Calendars.Read
Reads their diary so Find Advice never offers a time they are already busy.
Calendars.Read.Shared
Same, for a calendar that has been shared with them.
Calendars.ReadWrite
Writes the booking into their diary and updates or cancels it if the client reschedules.
Calendars.ReadWrite.Shared
Same, for shared or delegated calendars — needed where an assistant manages the diary.
MailboxSettings.Read
Reads their time zone and working hours so bookings land at the right local time.
offline_access
Keeps the sync running so they are not asked to sign in again every hour.
There is no mail, file, contact or company-wide access in that list. If you want to limit which staff can use it, leave consent granted and restrict access instead — see the next section.
Open LeadConnector → Properties. If Assignment required? is Yes, only assigned people can use it — add them under Users and groups → Add user/group. This is also the correct way to limit it to a few staff rather than the whole organisation.
If a reviewer without a consent-granting role opened the request, it may have been denied or left pending rather than approved. Confirm on the app’s Permissions → Admin consent tab.
A stale sign-in session can keep showing the old prompt. Sign out of Microsoft in that browser, then start Part 2 again.
Not the administrator? Copy the message below and send it to whoever manages your Microsoft 365.
Hi — I’m connecting my work calendar to our CRM (Find Advice, which connects through a Microsoft app called “LeadConnector”, published by Leadconnector LLC). When I try to connect, Microsoft says it needs admin approval.
Could you please grant admin consent to that app? In the Microsoft Entra admin center (https://entra.microsoft.com/): Entra ID → Enterprise apps → All applications → search “LeadConnector” → Permissions → Grant admin consent. It needs Cloud Application Administrator (or Privileged Role Administrator) — being listed as a consent-request reviewer is not enough on its own.
It asks only for delegated calendar permissions on my own account (Calendars.Read, Calendars.Read.Shared, Calendars.ReadWrite, Calendars.ReadWrite.Shared, MailboxSettings.Read, User.Read, offline_access) — no mail, files or company-wide access. I’ve already hit the approval screen once, so the app will show up in Enterprise apps.
If you would rather approve people individually, I can send a request from that screen instead — you’d approve it under Enterprise apps → Admin consent requests → My Pending. Thank you!
Once your IT team has approved LeadConnector (Part 1), do the steps below inside your own Find Advice account. Each person connects their own — an administrator cannot do it for you.
In Find Advice, click Settings (the gear icon at the bottom-left).
Open Calendars, then click the Connections tab at the top.
Click + Add New, then Connect next to Outlook Calendar.
Sign in with your Microsoft work account and click Accept. Once your IT team has approved LeadConnector, the “Approval required” screen will not appear.
Go to Settings → My Profile and scroll to the calendar settings.
Set Primary Calendar to your Outlook calendar. This is the calendar Find Advice reads to avoid clashes, and writes new bookings into.
Connecting Outlook does not connect Teams — it is a separate step. Do this if you want a Teams join link on every booking. You need a Microsoft Teams work or school account (personal Microsoft accounts are not supported).
In Settings → Calendars → Connections, scroll to the Video Conferencing section.
Click Add New (or Connect) next to Microsoft Teams, sign in with the same Microsoft work account, and approve.
Teams may ask for approval too
Teams can show its own one-time Microsoft approval prompt, even after Outlook was approved. If it is blocked, request it and your IT team approves it exactly the same way as Part 1.
So a Teams link is created automatically for every booking:
Go to Settings → Calendars and click Edit on the calendar people book on.
Open the Meeting Details tab and scroll to the Team Members section.
Set the meeting location to Microsoft Teams, then click Save. A unique Teams link now generates for each new booking and is added to the calendar invite.
A request only unblocks you once an administrator actually approves it — and only someone with a consent-granting role (Cloud Application Administrator or Privileged Role Administrator) can do that. Being listed as a reviewer of consent requests is not enough on its own; a reviewer without the role can view, deny or block a request but cannot approve it. This is the single most common reason a request sits there. The quickest way past it is Option A in Part 1 — the admin approves the app directly, without waiting on a request.
The LeadConnector app only appears in your organisation after someone has tried to connect. Attempt the calendar connection once (the “Approval required” screen is expected) — the app now exists under Enterprise apps → All applications and your admin can approve it there. For the request list specifically, it also has to be the My Pending tab: the “All” tab is history only and cannot be actioned.
Three things to check, in order: the app’s Permissions → Admin consent tab actually lists the calendar permissions; Properties → Assignment required? is either No, or you have been added under Users and groups; and you have signed out of Microsoft in that browser and tried again. All three are covered at the end of Part 1.
Teams can ask for an extra permission that was not in the first approval, so Microsoft prompts again. Have your admin approve it exactly the same way as Part 1.
That is normal. Copy the “Send this to your IT team” message in Part 1 and send it to whoever manages your Microsoft 365 — it names the app, the exact menu path, the role needed, and the exact permissions, so they can approve it without a back-and-forth.
The Microsoft Teams integration only works with a work or school (organisation) Microsoft account, not a personal one. Outlook calendar sync works with your work account too.
Your own calendar — to check your availability and add new bookings — your time zone and working hours, and, for Teams, to create online meeting links. Every permission is delegated, meaning it is scoped to your account and only works while you are signed in. There is no access to mail, files, contacts or anything organisation-wide. The full list, with the Microsoft Graph name behind each one, is in Part 1.