For partner ops whose partner cannot sign in with Microsoft, and for the IT admin at that partner who has to fix it.Microsoft sign-in works for most partners on the first try. At some partners, nobody gets in at first: everyone sees a Microsoft screen asking for admin approval, or lands back on the login page with “Sign-in was canceled”. That is not a problem with your portal or with their account. Their IT team has turned off the right of regular users to approve new apps, so an admin has to approve Introw once for the whole organization. Send this page to that admin.
What you’ll achieve
Everyone at the partner’s organization can sign in to your portal with their Microsoft work account. The admin approves once, and nobody at that partner has to ask again.Why it happens
Your portal uses Microsoft sign-in through Introw’s app in Microsoft Entra ID, the identity service behind Microsoft 365. The first time someone from a company signs in, Microsoft checks whether that person may approve the app themselves. Many organizations only let admins approve apps, which is a normal security setting. In those organizations, the first sign-in stops at a consent step until an admin grants approval for everyone. The approval covers Introw’s app, not one vendor’s portal. Once a partner’s admin has approved it, their people can sign in with Microsoft to every portal that runs on Introw, and to partners.introw.io.What Introw asks for
Introw only asks Microsoft to sign the person in and share their basic profile. It does not read mail, files, calendars, contacts, or anything else in the partner’s Microsoft 365.
These are delegated permissions: they only apply while the person is signed in, and only to that person’s own profile.
Steps for the partner’s IT admin
1
Sign in with an admin role
Use an account that holds Global Administrator, Cloud Application Administrator, or Application Administrator in Microsoft Entra ID.
2
Grant consent for the organization
Open the vendor’s partner portal and choose Sign in with Microsoft.
On the Microsoft consent screen, tick Consent on behalf of your organization, then select Accept.
Microsoft only shows this checkbox to admin roles.
If your organization uses admin consent requests, you can instead approve the pending request under Enterprise applications > Admin consent requests in the Microsoft Entra admin center.
3
Check the app is open to your users
In the Microsoft Entra admin center, go to Enterprise applications and
open the app named on the consent screen. Under Properties, make sure
Enabled for users to sign in? is set to Yes. If Assignment
required? is set to Yes, only assigned people can sign in, so assign the
users or groups who need the portal under Users and groups, or set it to
No.
4
Check Conditional Access
If a Conditional Access policy applies to all cloud apps, confirm it does not block this app for the people who need the portal.
A policy that requires multifactor authentication or a compliant device still works: people sign in the same way they sign in to Microsoft 365.
Verify it worked
Ask one person at the partner who was blocked before to open the portal and choose Sign in with Microsoft. They go straight through without a consent screen and land in the portal. If they now reach the portal but see that they have no access, sign-in works and the remaining step is on your side. See How a contact actually gets in.Microsoft error codes
Microsoft shows anAADSTS code on its error screen, and it tells the admin which step to look at.