Use Pin with Microsoft 365
4 min
the easiest way to enable pin with microsoft 365 is for an admin to log into pin and grant consent on behalf of your organization accept consent during login a microsoft 365 admin needs to log into pin using our consent link https //api pin com/auth/microsoft/consent https //api pin com/auth/microsoft/consent the admin will need to check "consent on behalf of your organization" so that other users can authenticate with pin allow access through microsoft entra id (previously "microsoft azure active directory" โ microsoft renamed this service in 2023 if your organization's admin portal still shows "azure active directory," you're in the same place; it's the same underlying service under its new name ) go to the microsoft entra admin center https //entra microsoft com to grant consent, or create a policy that allows the application you'll need to be signed in as at least a cloud application administrator , application administrator , or global administrator โ other roles won't be able to complete this step then follow the steps below in the microsoft entra admin center, go to enterprise applications >all applications search for "pin" in the list of applications if pin doesn't appear in this list the app is only provisioned in your tenant after at least one user has completed the consent link ( https //api pin com/auth/microsoft/consent ) if it's missing, have a user complete that step first, then check again open the application, select properties , and switch "enabled for users to sign in?" to yes this enables pin and allows your users to authenticate next, go to security > permissions on that same application page review the listed permissions, then click grant admin consent for \[your organization] confirm in the microsoft consent popup that appears verify it worked back on the permissions page, you should now see the granted permissions listed with consent type allprincipals โ this confirms consent was granted tenant wide, not just for a single user shortcut โ pending requests if your organization has the admin consent workflow enabled, a request may already be waiting for approval go to enterprise applications > activity > admin consent requests > my pending to approve it directly without the manual steps above frequently asked questions if you're looking for why we need these permissions, please review the below permission purpose openid authenticates and signs the user in email reads the user's email address for identification profile reads basic profile information, such as name offline access allows the connection to remain active and refresh tokens without repeated sign in user read reads the signed in user's microsoft profile mail readwrite reads, synchronizes, and manages mailbox messages it does not permit sending by itself mail send sends email as the connected user|mailbox calenders readwrite synchronizes and manages calendar events pylon uses calendar data to backfill meetings and populate fields such as last meeting date and next meeting date


