Connect your accounts

Connect Outlook / Microsoft 365

Connect Outlook or Microsoft 365 to Prosyo and fix "Need admin approval", AADSTS90094 and AADSTS65001 by granting admin consent in Microsoft Entra.

On this page

Connect an Outlook.com or Microsoft 365 work mailbox with Microsoft sign-in. Prosyo sends your email steps from it and syncs replies into your Inbox.

Who can connect one#

  • Multichannel: 1 Gmail/Outlook account included
  • Agency / Team: 1 Gmail/Outlook account per billed seat
  • Any paid plan with an extra LinkedIn/email seat
Upgrade

Outlook needs a Multichannel or Agency / Team plan, or an extra LinkedIn/email seat. See plans.

Connect#

  1. Go to Settings → Accounts.
  2. In the Gmail / Outlook card, click Connect account, then choose Outlook in the connection window.
  3. Sign in with the Microsoft account you want to send from.
  4. Review the permissions and click Accept.
  5. You're returned to Prosyo. The mailbox shows Healthy.

Personal Outlook.com, Hotmail and Live accounts usually connect straight away. Work and school accounts may need an admin to approve the app first, as described below.


Error: "Need admin approval"#

Most Microsoft 365 organizations only let admins approve apps that read and send mail. If yours does, you'll see a screen like this instead of the permission prompt:

Need admin approval [App name] needs permission to access resources in your organization that only an admin can grant. Please ask an admin to grant permission to this app before you can use it.

You may also see an error code:

CodeMeaning
AADSTS90094Admin consent is required for the permissions requested
AADSTS65001The user or administrator has not consented to use the application
AADSTS900971 / AADSTS50020You signed in with the wrong account type or tenant. Try again with your work account.

Before you close the error, write down:

  1. The app name shown on the screen.
  2. The Application (client) ID. Click Show details or Having trouble? → Details on the Microsoft screen to see it.

Your admin needs these to find the app.

Option A: Ask for approval from the error screen#

If the screen shows a Request approval button, fill in why you need it (for example "Sales outreach via Prosyo") and click Request approval. Your admin gets an email. Once they approve it, go back to Prosyo and click Connect account → Outlook again.

A Global Administrator, Cloud Application Administrator or Application Administrator does this:

  1. Trigger the app once. Ask the user to try connecting in Prosyo so the app is registered in your tenant. Or the admin can try connecting themselves.
  2. Sign in to the Microsoft Entra admin center at https://entra.microsoft.com.
  3. Go to Identity → Applications → Enterprise applications → All applications.
  4. Search for the app name or Application (client) ID from the error message and open it.
  5. Go to Security → Permissions.
  6. Click Grant admin consent for [your organization].
  7. Sign in with the admin account and click Accept.
  8. Ask the user to go back to Prosyo and click Connect account → Outlook again.

If the app doesn't appear in step 4, the admin can sign in to Prosyo, start the Outlook connection themselves, and tick Consent on behalf of your organization on the permission screen before clicking Accept.

If your organization wants users to connect approved mail apps on their own:

  1. In Microsoft Entra admin center, go to Identity → Applications → Enterprise applications → Consent and permissions → User consent settings.
  2. Choose Allow user consent for apps from verified publishers, for selected permissions (or the policy your security team prefers).

This is an organization-wide change. Most teams should use Option B instead.

SymptomWhat to check
Error continues after admin consentWait 5 to 10 minutes for Microsoft to update, then sign out of Microsoft in your browser and connect again.
"User assignment required"In the enterprise app, go to Properties and set Assignment required? to No, or add the user under Users and groups.
Conditional Access blocked sign-inYour security team must allow the app or your location under Protection → Conditional Access.
Mailbox connects but sending failsThe mailbox needs an Exchange Online license. Shared mailboxes need a licensed user with Send As rights.
Tip

Forward this page to your IT team. Everything they need is in Option B.


Alternative: connect with SMTP/IMAP#

If your organization won't approve the app, you can connect the same mailbox as a custom SMTP/IMAP mailbox. This needs Authenticated SMTP turned on for the mailbox instead.

Good habits#

  • Warm up a new mailbox: start near 25 emails per day.
  • Make sure SPF, DKIM and DMARC are set for your domain. In Microsoft 365, DKIM is under Microsoft Defender → Email & collaboration → Policies → Email authentication settings.

Disconnect#

On Settings → Accounts, click Disconnect next to the mailbox. Campaigns that use it pause until you choose another email account. You can also remove access at https://myapps.microsoft.com or https://account.live.com/consent/Manage for personal accounts.