> For the complete documentation index, see [llms.txt](https://docs.rox.com/development/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.rox.com/development/engineering/docs/rox-enterprise-integrations/granting-microsoft-integration-permissions-for-rox.md).

# Granting Microsoft Integration Permissions for Rox

This guide walks through connecting a Microsoft 365 individual integration (Outlook Calendar / Outlook Mail) to Rox when your tenant requires admin consent. The flow spans both the end user and the Microsoft admin — follow the steps in order. (For orgwide integration refer this [doc](https://docs.rox.com/development/engineering/docs/rox-enterprise-integrations/orgwide-integration-via-microsoft-graph))

***

### Step 1 — Start the connection from Rox *(end user)*

From the Rox **Integrations** page, find the Microsoft integration (for example, **Outlook Calendar**) and click **Connect**.

Review the read/write access scopes Rox is requesting and click **Connect** to proceed.

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FGjp42qiO01V2w34BIsNy%2Fimage.png?alt=media&amp;token=d4310170-0a25-4bff-b17e-b3b765ea5257" alt=""><figcaption></figcaption></figure>

### Step 2 — Request admin approval *(end user)*

You are redirected to Microsoft. If your tenant requires admin consent, an **Approval required** screen appears for **Rox 365 Integration** (publisher: **Rox Data Corp.**) listing the requested permissions:

* Read user calendars
* Have full access to user calendars
* View users' basic profile
* Maintain access to data you have given it access to

Enter a short justification (e.g., *"I want to sync my data to Rox"*) and click **Request approval**.

Microsoft approval required screen

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FyxJxEFoBPKHXccHsLhfx%2Fimage.png?alt=media&amp;token=447edf60-b51c-4604-b9e7-c22b93eff9d8" alt=""><figcaption></figcaption></figure>

### Step 3 — Confirmation that the request was sent *(end user)*

Microsoft displays a **Request sent** confirmation. Your admin is notified and you will receive an email once the request is reviewed. You can close this tab and wait for approval.

Microsoft request sent screen

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2F6ZGZ2joWNzZi9CzMjgAv%2Fimage.png?alt=media&amp;token=a5e1e977-ea66-439c-81ae-110207f6df54" alt=""><figcaption></figcaption></figure>

### Step 4 — Open the consent request queue *(Microsoft admin)*

The admin signs in to the [Microsoft Entra admin center](https://entra.microsoft.com/) as a Global Administrator (or an Application Administrator with consent privileges) and navigates to **Entra ID → Enterprise apps → Admin consent requests**.

Pending requests for **Rox 365 Integration** appear under the **My Pending** tab. Select the request to open the details pane, verify the requester (UPN) and justification, then click **Review permissions and consent**.

Entra admin consent requests queue

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FSMM8pBsJ1zjqz2lEDXK5%2Fimage.png?alt=media&amp;token=05c065ef-52ac-496e-960b-7e4778f8576a" alt=""><figcaption></figcaption></figure>

### Step 5 — Grant consent on behalf of the organization *(Microsoft admin)*

A Microsoft consent dialog opens listing the permissions. Verify the publisher is **Rox Data Corp.** (verified badge visible) and click **Accept**.

This grants the permissions tenant-wide — no other user in your organization will be prompted again.

Microsoft permissions requested screen

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2Fv4QcEPIjHWSCNooIWZQn%2Fimage.png?alt=media&amp;token=324895cb-1dc4-4b89-9c99-5a477884ef2a" alt=""><figcaption></figcaption></figure>

### Step 6 — Verify granted permissions *(Microsoft admin)*

To confirm the consent was applied, go to **Enterprise apps → Rox → Permissions**. Under the **Admin consent** tab, the granted Microsoft Graph permissions should be listed, for example:

| API name        | Claim value           | Permission                         | Type      |
| --------------- | --------------------- | ---------------------------------- | --------- |
| Microsoft Graph | `Calendars.Read`      | Read user calendars                | Delegated |
| Microsoft Graph | `Calendars.ReadWrite` | Have full access to user calendars | Delegated |

Entra Rox app permissions page

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FCYgeH44tq2kfmPzFmiVt%2Fimage.png?alt=media&amp;token=3b523d7b-723f-475f-9035-5aa62a9ec58a" alt=""><figcaption></figcaption></figure>

### Step 7 — Finish the connection in Rox *(end user)*

Once the admin has approved, the requesting user returns to Rox and clicks **Connect** again on the integration tile to complete the connection. No further Microsoft prompts should appear.

#### User Troubleshooting

If you are still unable to connect, please navigate to <https://myapps.microsoft.com/> and search for "Rox 365 Integration".

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FprohMt9Z0sIQ0qQTSWRH%2FScreenshot%202026-05-05%20at%205.48.14%E2%80%AFPM.png?alt=media&amp;token=7bf6815c-b078-44f5-b34f-50738eace420" alt=""><figcaption></figcaption></figure>

Ensure that the permissions that your admin consented to are visible here.

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FIHB9zQok5kNrb1U37Dfq%2FScreenshot%202026-05-06%20at%207.09.45%E2%80%AFPM.png?alt=media&amp;token=66919fc6-b3f4-47cc-bbb5-ea89923182aa" alt=""><figcaption></figcaption></figure>
