Microsoft 365 admin: approving Coastline CRM for email and calendar
If users in your organization see a "Need admin approval" screen when connecting their work email or calendar to Coastline CRM, follow these steps to grant consent and unblock them.
Why you're seeing this
A teammate using Coastline CRM tried to connect their Microsoft 365 work email or calendar, and Microsoft returned a "Need admin approval" screen. Their connection didn't go through.
This is by design. Your organization's Microsoft 365 settings only allow administrators to approve which third-party applications can access organizational data like mail and calendars. Coastline CRM is a third-party application, so a tenant administrator needs to approve it once. After that, any user you authorize can connect on their own without seeing the screen again.
This article walks through the three ways to grant that approval. Each path takes a few minutes and only needs to be done once per organization.
One app, permissions requested in steps
Coastline CRM is a single registered application in Microsoft (one Application ID, listed below). That same application powers all three Microsoft features in Coastline: signing in with Microsoft, connecting your email, and connecting your calendar. You are approving one application, not a separate one for each feature.
Coastline also requests permissions progressively, asking only for what each action needs, at the moment a user takes it:
- Signing in with Microsoft asks only to verify the user's identity (sign in and read basic profile). Nothing more.
- Connecting email additionally asks for mail permissions, so the user can read and send their own mail from inside Coastline.
- Connecting a calendar additionally asks for calendar permission, so the user can see and manage their own events from inside Coastline.
Because the permissions are requested in steps, the exact list shown on the "Permissions requested" screen depends on which connection a user was making when the prompt appeared. Granting admin consent (any of the options below) approves the Coastline CRM application for your organization, so your team can connect without hitting the approval screen for the permissions you've granted.
What you'll see on the approval screen
When you approve, Microsoft shows a screen titled Permissions requested, with the subtitle Review for your organization. At the top, the publisher is listed as COASTLINE CRM LLC with a blue verified-publisher checkmark next to it. That badge confirms the publisher's identity has been verified by Microsoft. The definitive check that this is the genuine app is the Application (client) ID, listed in the next section. If you do not see the verified checkmark, stop and contact support before approving.
Under "This app would like to:" you'll see the permissions for whichever connection triggered the prompt. Because Coastline requests permissions in steps, the screen lists only what that step needs, not the full set. The bold text is the plain-language label Microsoft shows on the screen; the value in parentheses is the underlying technical permission name, so your IT team can match either one.
Signing in with Microsoft requests only identity:
- Sign you in and read your basic profile (
openid,profile,email): confirms who the user is. Signing in requests nothing beyond this.
Connecting email additionally requests:
- Read and write access to user mail (
Mail.ReadWrite): lets a connected user read and manage their own mailbox from inside Coastline. - Send mail as a user (
Mail.Send): lets a connected user send email as themselves from inside Coastline. - Sign in and read user profile (
User.Read): reads the connected mailbox owner's basic profile. - Maintain access to data you have given it access to (
offline_access): keeps the connection alive after the browser closes, so scheduled sends and ongoing sync keep working.
Connecting a calendar additionally requests:
- Read and write user calendars (
Calendars.ReadWrite): lets a connected user see and manage their own calendar events from inside Coastline. - Maintain access to data you have given it access to (
offline_access): keeps the connection alive so calendar sync keeps working in the background. - Plus the same basic identity (
openid,profile,email).
So if a user only connected email, the screen lists the email permissions; if they only connected a calendar, it lists the calendar permissions. Either way, you are approving the same Coastline CRM application.
Below the list, Microsoft notes: "If you accept, this app will get access to the specified resources for all users in your organization. No one else will be prompted to review these permissions." That is expected. Approving once covers everyone you allow to connect, which is the whole point of an admin approval.
All of these are delegated permissions. Coastline can only ever act on behalf of a user who has individually signed in and connected their own mailbox or calendar. There are no application-level permissions, so Coastline cannot read anyone's data without that specific person connecting first.
App identifiers (verify before approving)
So you can confirm you're approving the correct application, here are Coastline CRM's identifiers in the Microsoft identity platform. These are the same for signing in, email, and calendar, because they are all the same application:
- Application name: Coastline CRM
- Publisher: COASTLINE CRM LLC (verified)
- Application (client) ID:
89894101-7faf-4d00-9815-7d629c0f670a - Publisher domain: coastlinecrm.com
If the application in your tenant shows a different Application ID, stop and email support@coastlinecrm.com before approving.
Option 1: Use the admin-consent shortcut link (recommended)
The fastest way to approve Coastline CRM is a one-click consent link. It grants consent for all of the permissions the application is registered to require, in a single step, and it works even if no one in your organization has tried to connect yet. You need to be signed in as a Global Administrator or Cloud Application Administrator.
- Open this link in a browser session where you're signed in with your administrator account:
(If you prefer, you can replacehttps://login.microsoftonline.com/organizations/adminconsent?client_id=89894101-7faf-4d00-9815-7d629c0f670a&redirect_uri=https%3A%2F%2Fwww.coastlinecrm.com%2Fadmin-consentorganizationswith your own tenant ID. Avoidcommonfor admin consent, as it can route you into a personal-account context that cannot grant organizational approval.) - Microsoft shows the Permissions requested screen (the one described under "What you'll see on the approval screen" above), listing the permissions and the verified COASTLINE CRM LLC publisher.
- Review the permissions and click Accept.
- After you accept, you will land on a Coastline CRM page confirming the approval was recorded for your organization.
- Have the affected user retry connecting from inside Coastline CRM. The "Need admin approval" screen will not appear again.
Option 2: Approve from the Microsoft Entra admin center
Use this path if you'd prefer to review the application in your admin console before granting consent. It reaches the same result as the shortcut link, just with a manual review step.
- Sign in to the Microsoft Entra admin center as a Global Administrator or Cloud Application Administrator.
- Go to Identity → Applications → Enterprise applications.
- In the All applications list, search for
Coastline CRM.- If the application doesn't appear, no one in your tenant has triggered a consent prompt yet. Ask the affected user to attempt the connection once. Their failed attempt is enough to register the application in your tenant. Refresh the list and Coastline CRM will appear. (The shortcut link in Option 1 does not need this; it works before anyone has tried to connect.)
- Click Coastline CRM to open it.
- In the left menu, click Security → Permissions.
- Click Grant admin consent for [your organization].
- The Permissions requested screen described above appears. Confirm the verified COASTLINE CRM LLC publisher, review the permissions, and click Accept.
- The Permissions page will now show the granted permissions with a green check mark. The block is lifted.
Tell the user who hit the original block to retry connecting their email or calendar from inside Coastline CRM. The "Need admin approval" screen will not appear again.
Option 3: Approve per-user requests instead
If your organization's policy is to keep application consent strictly opt-in per user, you can leave the default block in place and approve each user's request individually. This requires the admin consent request workflow to be enabled on your tenant.
- Sign in to the Microsoft Entra admin center.
- Go to Identity → Applications → Enterprise applications → Consent and permissions → Admin consent settings.
- Confirm that Users can request admin consent to apps they're unable to consent to is set to Yes, and that at least one reviewer is configured.
- Once this is on, the next time a user hits the "Need admin approval" screen, they will see a Request approval option. When they submit a request, you'll receive an email notification, and the request will appear under Admin consent requests in the admin center.
- Open the Coastline CRM request, review the permissions, and click Approve. The user will be notified and can retry.
Email and calendar use the same app
Email and calendar are two separate connections inside Coastline, and each is requested as its own step, so a user can connect one without the other. But both run through the same Coastline CRM application you approve here. You never approve a different app for one versus the other.
In most organizations, approving the Coastline CRM application once covers both the email and the calendar connection, because you are approving a single registered application. If your tenant is set up to consent to permissions one at a time, an administrator might occasionally see one more approval prompt the first time someone connects the second feature. If that happens, approve it the same way. You are always approving the same Coastline CRM application (Application ID 89894101-7faf-4d00-9815-7d629c0f670a), just adding the permission the new connection needs. Either approval option grants all of the permissions the application is registered to require in one place, so a single approval normally covers both connections.
Restrict access to a specific group (optional)
By default, granting consent makes Coastline CRM available to any user in your tenant who tries to connect. To allow only a specific group of users (for example, your sales team) to connect:
- In the Entra admin center, go to Identity → Applications → Enterprise applications → Coastline CRM.
- Open Properties in the left menu.
- Set Assignment required? to Yes and save.
- Open Users and groups in the left menu.
- Click Add user/group and assign the people or groups who should be allowed to connect.
Anyone outside the assigned set will be unable to connect.
Revoking access later
If you ever want to disconnect Coastline CRM from your organization:
- In the Entra admin center, go to Identity → Applications → Enterprise applications → Coastline CRM.
- Click Delete at the top of the application page.
- Confirm. All consent grants are revoked and every user in your organization is disconnected.
Individual users can also disconnect their own mailbox or calendar from inside Coastline CRM at any time, without affecting anyone else. Deleting the application at the Entra level cuts the whole organization off at once.
Troubleshooting
The application doesn't appear in Enterprise applications. A user has to trigger the consent prompt at least once for the application to register in your tenant. Ask the affected user to attempt the connection once. The failed attempt is enough. Then refresh the Enterprise applications list.
Clicking the admin-consent shortcut shows "AADSTS90094: The grant requires admin permission." Your browser session is signed in as a non-admin account. Open a private window, sign in there as a Global Administrator or Cloud Application Administrator, then reopen the shortcut link.
A user still sees the approval prompt for a different permission after consent was granted. Coastline requests permissions in steps, so a user who connected email earlier may trigger a fresh approval step the first time they connect a calendar (or the reverse). Approve it the same way; it is the same Coastline CRM application, just adding the new connection's permission. If the prompt persists for a permission you already granted, Microsoft consent state can take several minutes to propagate. If it lasts more than an hour, open the Coastline CRM application in the Entra admin center and check Properties → Assignment required?. If it's set to Yes with no users in Users and groups, that combination blocks every non-administrator who isn't assigned. Either set Assignment required? to No, or add the affected users. Global administrators can still connect even when unassigned, so test with an affected non-admin user rather than your own admin account.
You want a non-administrator to be able to approve future application requests. In the Entra admin center, go to Identity → Roles & admins and assign the Cloud Application Administrator role to that user. They'll be able to grant consent for any application without needing full Global Administrator rights.
Still stuck?
Reach out to Coastline CRM support at support@coastlinecrm.com and include:
- The error message shown in the Entra admin center, including the AADSTS code if there is one.
- Whether Coastline CRM appears under Enterprise applications.
- Your tenant ID (on the Overview page in the Entra admin center, copy the Tenant ID).
We'll respond within one business day.
Was this article helpful?
Still need help?
Submit a ticket and a human will get back to you.
More in Calendar
How does calendar sync work?
Two-way sync with Google Calendar and Outlook.
How do I share a booking link?
Let prospects pick a time on your calendar without the back-and-forth.
How do I create a calendar event and invite a contact?
Schedule a meeting, drag in a contact, and Coastline sends the invite for you.
How do I set my working hours and timezone for scheduling?
Define when you're open for booked meetings so prospects can only pick valid times.