If you see the following message when trying to connect your Microsoft 365 account to BaseCloud CRM, it means your organisation’s Microsoft tenant does not allow standard users to approve third-party apps. Someone with administrator rights has to authorise BaseCloud CRM once, after which every user in the organisation can connect normally.
Error: “Need admin approval” (Error Code AADSTS90094)
Who can approve this:
A Global Administrator or a Cloud Application Administrator on your Microsoft 365 tenant. If you don’t know who that is, it’s usually your IT provider or whoever set up your company email.
Option 1: Approve from the sign-in screen (fastest)
- Have the administrator start the connection
- Ask your Global Administrator to open BaseCloud CRM and start the Microsoft 365 connection
- They should sign in with their own administrator account
- Tick the organisation-wide option
- On the permissions screen, tick “Consent on behalf of your organization”
- Review the permissions listed, then click Accept
- Retry your own connection
- Return to BaseCloud CRM with your normal account and connect your mailbox again
Option 2: Approve from the Microsoft Entra admin center
- Sign in to the Entra admin center
- Go to https://entra.microsoft.com
- Sign in with a Global Administrator or Cloud Application Administrator account
- Open your enterprise applications
- In the left menu, go to Entra ID → Enterprise apps → All applications
- Find BaseCloud CRM
- Search for BaseCloud CRM and select it from the results
- If it isn’t listed, no one has attempted a connection yet — use Option 1 above instead
- Open the app’s permissions
- In the left menu of the app, under Security, select Permissions
- Grant consent
- Review the permissions the app is requesting
- Click Grant admin consent for [your organisation]
- Confirm your sign-in if prompted, then select Accept
- Confirm and retry
- The permissions should now show as granted for your organisation
- The user can return to BaseCloud CRM and connect their mailbox
If a request was already submitted
When a user hits the error, Microsoft sometimes lets them send an approval request to their administrator. To find it:
- Go to Entra ID → Enterprise apps → Admin consent requests
- Select the BaseCloud CRM request
- Click Review permissions and consent, then approve it
Still not working?
If consent has been granted but the connection still fails:
- Give it time to sync. Microsoft can take 10–30 minutes to apply the change across its systems.
- Check that user assignment isn’t blocking it. Go to Enterprise apps → BaseCloud CRM → Properties. If Assignment required is set to Yes, the user must be added under Users and groups.
- Check for Conditional Access policies. Some tenants block third-party applications outright. Your administrator will need to allow BaseCloud CRM.
- Confirm the mailbox is licensed. The account needs an active Microsoft 365 licence with an Exchange Online mailbox.
- Reset the app. As a last resort, go to Enterprise apps → BaseCloud CRM → Delete, wait 20–30 minutes, then start the connection again from BaseCloud CRM.
