manyCalendars
  • Features
  • Pricing
  • Help
Install Free
TROUBLESHOOTING

The "Need admin approval" calendar app screen, explained

Updated: July 3, 2026 · 5 min read

What that screen actually means

You tried to connect a calendar tool to your work Microsoft account and hit a full stop: "Need admin approval. This app needs permission to access resources in your organization that only an admin can grant." If you searched need admin approval calendar app and landed here, you are probably staring at that screen right now. Here is what it means, why waiting for approval usually goes nowhere, and how to get every calendar into one view without asking anyone.

The screen is not an error. It is Microsoft working as designed. The app you tried to connect asked Microsoft for API access to your calendar, usually a permission called Calendars.Read or Calendars.ReadWrite. Your organization's Microsoft Entra tenant is configured so that individual users cannot grant those permissions themselves. Only an Entra administrator can. Until one does, the connection is dead. There is nothing you can click, and nothing the app vendor can do from their side.

Why you are seeing it more since November 2025

This screen used to be rare. Since November 2025, it is the default. Microsoft changed Entra's default settings so that user consent to third-party apps requesting calendar permissions is blocked out of the box. Before, many organizations allowed users to approve low-risk permissions themselves. Now, unless an admin has deliberately loosened the setting, every new calendar app connection lands on this wall.

One detail explains a lot of confusion: existing grants were grandfathered. If a coworker connected the same app in 2024, their connection still works. Yours will not, because yours is new. Same app, same company, different outcome. We wrote a full explainer on the change in Microsoft blocks calendar apps by default.

Will your admin click approve? Honestly, probably not

Some tenants show a "request approval" box under the error. Many show nothing at all, just a dead end. Even when the request path exists, understand what you are asking for. Admin consent is tenant-wide: the admin is not approving the app for you, they are approving a third-party company's servers to request calendar data for anyone in the organization. That triggers a security review at most companies. Vendor questionnaires, data residency questions, legal sign-off. Weeks if you are lucky.

If you are a consultant or contractor, it is harder still. You are asking a client's IT team to accept organizational risk so that your personal scheduling gets easier. That request sits at the bottom of every queue, and at some clients you have no way to even file it. None of this is admin malice. Blocking consent phishing and OAuth token abuse is a legitimate defense. It just leaves you with a calendar problem.

If you want to try for approval anyway

It can work, especially at a small company with a responsive IT person. Give them everything they need in one message:

  1. Name the app and the exact permission it requests, usually Calendars.Read (read-only) rather than Calendars.ReadWrite.
  2. Link the vendor's own admin-approval documentation. CalendarBridge, OneCal, Reclaim.ai, and Morgen all publish help articles for exactly this situation, because their OAuth model requires each account to be connected and managed tenants block that by default.
  3. Say why: cross-client conflict prevention is a business justification, not a convenience.

Then set a reminder, because you may be waiting a while. If the answer is no, or no answer comes, keep reading.

What works instead: skip the permission request entirely

The approval screen exists only because the app asked Microsoft's servers for API access. A tool that never asks never hits the wall. That is the whole idea behind manyCalendars, and as far as we know it is the only calendar tool that works when IT says no.

manyCalendars is a desktop browser extension that shows all your calendars in one view, entirely on your machine. Two ways in, neither of which involves an admin:

  • Manual calendars. Add unlimited .ics files and feed URLs on the free tier. No account, no sign-in, 100 percent local.
  • Tab Sync. For accounts where feeds and export are locked down, open your Outlook or Google calendar in a browser tab like you already do, and sync it. From then on, that calendar follows its tab. No OAuth request, no token, nothing for an admin to approve, because your browser already shows you your own calendar.

The honest limits: it is a desktop browser extension only, there is no phone app. Tab Sync reads what is visible in a tab you are signed into, and it is read-only on the source. It will not create or edit events in Outlook or Google for you. If you need true two-way sync between accounts and you can get approval, a cloud sync service is the better fit; see below.

Tab Sync is part of Pro at 15 dollars a month or 150 dollars a year. The free tier handles unlimited feed-based calendars forever. Every install starts a 14-day full trial of everything, no card and no account. Install it free or see the full pricing.

If your admin will approve, cloud sync tools are good

Fair is fair. If admin approval is available to you, OAuth-based sync services do things a local tool cannot. CalendarBridge, for example, offers patented server-mediated two-way sync, booking pages, and a HIPAA BAA, at 4, 8, or 32 dollars per user per month depending on plan. If both of your organizations will authorize it, it is a solid product. We compare the two approaches honestly in manyCalendars vs CalendarBridge.

The difference is what happens when approval never comes. A cloud sync tool without consent is a login screen. A local tool keeps working, because it never needed permission to begin with. For a broader look at your options, start with the complete guide to calendars without admin approval.

Common questions

Can I bypass the screen myself?

No. The block is enforced server-side by your organization's Entra settings. No browser trick changes it, and anything claiming to should worry you. The real choices are admin approval or a tool that never requests API access.

Why does the same app work for my colleague?

Grants issued before the November 2025 default change were grandfathered. They connected while user consent was still allowed. New connections hit the wall.

Does this affect my personal Outlook.com or Gmail account?

No. Tenant consent policy governs work and school accounts. Personal accounts can still authorize apps directly, though managed Google Workspace accounts have their own admin controls that can behave similarly.

Is reading my calendar from a browser tab allowed?

You are viewing your own calendar in a tab your organization already lets you sign into. manyCalendars reads what is already on your screen and keeps it locally on your machine. Nothing goes to our servers, and nothing is written back to the source calendar. If you are unsure, check your client or employment agreements.

Related reading

  • Calendar without admin approval: the complete guide
  • Microsoft blocks calendar apps by default: what changed in November 2025
  • Merge calendars without OAuth
  • See the calendars IT blocked
manyCalendars

One view for every calendar. No IT approval. Built for contractors, by a contractor.

Product

Features Pricing Roadmap Changelog Security

Resources

Docs Help Center Blog Status

Legal

Privacy Policy Terms of Service DPA Fair Use
© 2026 manyCalendars. All rights reserved.