What you need to do to grant Gravyty admin access
Gravyty is a third-party application that integrates with Office 365 to help manage email and communications. To use it, you must first give it permission to access your organization's data. This permission process is called admin consent, and it requires someone with global administrator rights in your Office 365 tenant to approve it.
The approval happens through the Azure Active Directory consent screen. When you or another user first tries to sign into Gravyty with an Office 365 account, they will see a permissions request. If you are a global admin, you can approve it immediately. If you are not, you need to ask your global admin to complete the approval.
Key Takeaways
- Only a global administrator in your Office 365 tenant can grant admin consent for Gravyty to access organizational data.
- The approval happens on a permissions screen that appears when someone first signs into Gravyty with an Office 365 account.
- You must click "Accept" on the consent screen and confirm that you are authorizing Gravyty to access your organization's information.
- After approval, all users in your organization can sign into Gravyty without seeing the consent screen again.
- If you need to revoke access later, you can remove Gravyty from your Azure Active Directory enterprise applications.
Steps to approve Gravyty through the consent screen
When a user with global admin rights signs into Gravyty for the first time using their Office 365 account, they will see a permissions request screen. This screen lists the data and functions that Gravyty needs to access, such as reading email, accessing calendar information, or managing contacts.
Read through the permissions listed. If you agree that Gravyty should have access to these functions, click the "Accept" button at the bottom of the screen. You may be asked to confirm your identity with a second authentication factor, depending on your organization's security settings.
Once you click "Accept," the approval is recorded in your Azure Active Directory. Gravyty is now authorized to access your organization's Office 365 data. Other users in your organization can now sign into Gravyty without seeing this consent screen.
What permissions Gravyty typically requests
Gravyty usually requests permission to read and send emails, access calendar data, and read contact information from your organization's directory. The exact permissions depend on which Gravyty features your organization plans to use.
Common permissions include reading mail folders, sending mail on behalf of users, accessing calendar events, and reading user profiles and organizational information. These permissions allow Gravyty to integrate with Outlook and other Office 365 services to perform its core functions.
If you are unsure whether a permission is necessary, contact Gravyty support before approving. You can also review the permissions again later by going to your Azure Active Directory settings.
How to check or revoke Gravyty access later
After you grant approval, you can view or remove Gravyty's access at any time through the Azure Active Directory admin center. Sign in to the Azure Active Directory admin center with your global admin account and navigate to Enterprise applications.
Search for "Gravyty" in the list of applications. Click on it to open the application details page. From here, you can see which permissions Gravyty has been granted and who in your organization has signed in.
If you want to remove Gravyty's access entirely, click the "Delete" button on the application details page. This will revoke all permissions and sign out all users. If you only want to remove access for specific users, you can manage user assignments on the same page.
Troubleshooting common approval issues
If the consent screen does not appear when you sign into Gravyty, it may mean that approval has already been granted by another admin in your organization. Check with your IT department or other global admins to confirm.
If you see an error message saying you do not have permission to grant consent, you are not signed in with a global administrator account. Only global admins can approve third-party applications for the entire organization. Contact your global admin and ask them to complete the approval process.
If Gravyty is not appearing in your Azure Active Directory after you approved it, wait a few minutes for the system to sync. If it still does not appear after 15 minutes, try signing out of Gravyty and signing back in with your Office 365 account to trigger the approval process again.
Who needs to approve Gravyty and when
Only one person needs to grant admin consent for Gravyty. That person must be a global administrator in your Office 365 tenant. Once they approve it, the application is authorized for your entire organization, and all other users can sign in without additional approval steps.
You should arrange for approval before rolling out Gravyty to your team. If a non-admin user tries to sign in first, they will see a message saying they cannot grant consent and will need to ask an admin. This can delay deployment, so coordinate with your global admin ahead of time.
Frequently Asked Questions
Can a user who is not a global admin grant Gravyty approval?
No. Only global administrators can grant admin consent for third-party applications in Office 365. If a non-admin user tries to sign into Gravyty, they will see a message asking them to request approval from an admin. They cannot complete the approval themselves.
Do all users need to approve Gravyty individually?
No. Once a global admin grants approval, all users in your organization can sign into Gravyty without seeing the consent screen. The approval applies organization-wide, not per user.
What happens if I accidentally deny the permissions?
If you click "Deny" on the consent screen, Gravyty will not be authorized. To approve it, sign back into Gravyty with your global admin account and the consent screen will appear again. You can then click "Accept" to grant the permissions.
Can I change which permissions Gravyty has after I approve it?
You cannot modify individual permissions through the consent screen. If Gravyty requests new permissions in the future, you will see an updated consent screen when you next sign in. You can approve or deny the new permissions at that time. To remove all permissions, delete Gravyty from your Azure Active Directory enterprise applications.
How long does it take for Gravyty approval to take effect?
Approval usually takes effect immediately after you click "Accept" on the consent screen. Other users should be able to sign in right away. If there is a delay, wait a few minutes and try signing in again.