Skip to main content
For partner ops whose partner cannot sign in with Microsoft, and for the IT admin at that partner who has to fix it.
Microsoft sign-in works for most partners on the first try. At some partners, nobody gets in at first: everyone sees a Microsoft screen asking for admin approval, or lands back on the login page with “Sign-in was canceled”. That is not a problem with your portal or with their account. Their IT team has turned off the right of regular users to approve new apps, so an admin has to approve Introw once for the whole organization. Send this page to that admin.

What you’ll achieve

Everyone at the partner’s organization can sign in to your portal with their Microsoft work account. The admin approves once, and nobody at that partner has to ask again.

Why it happens

Your portal uses Microsoft sign-in through Introw’s app in Microsoft Entra ID, the identity service behind Microsoft 365. The first time someone from a company signs in, Microsoft checks whether that person may approve the app themselves. Many organizations only let admins approve apps, which is a normal security setting. In those organizations, the first sign-in stops at a consent step until an admin grants approval for everyone. The approval covers Introw’s app, not one vendor’s portal. Once a partner’s admin has approved it, their people can sign in with Microsoft to every portal that runs on Introw, and to partners.introw.io.

What Introw asks for

Introw only asks Microsoft to sign the person in and share their basic profile. It does not read mail, files, calendars, contacts, or anything else in the partner’s Microsoft 365. These are delegated permissions: they only apply while the person is signed in, and only to that person’s own profile.

Steps for the partner’s IT admin

1

Sign in with an admin role

Use an account that holds Global Administrator, Cloud Application Administrator, or Application Administrator in Microsoft Entra ID.
2

Grant consent for the organization

Open the vendor’s partner portal and choose Sign in with Microsoft. On the Microsoft consent screen, tick Consent on behalf of your organization, then select Accept. Microsoft only shows this checkbox to admin roles. If your organization uses admin consent requests, you can instead approve the pending request under Enterprise applications > Admin consent requests in the Microsoft Entra admin center.
3

Check the app is open to your users

In the Microsoft Entra admin center, go to Enterprise applications and open the app named on the consent screen. Under Properties, make sure Enabled for users to sign in? is set to Yes. If Assignment required? is set to Yes, only assigned people can sign in, so assign the users or groups who need the portal under Users and groups, or set it to No.
4

Check Conditional Access

If a Conditional Access policy applies to all cloud apps, confirm it does not block this app for the people who need the portal. A policy that requires multifactor authentication or a compliant device still works: people sign in the same way they sign in to Microsoft 365.

Verify it worked

Ask one person at the partner who was blocked before to open the portal and choose Sign in with Microsoft. They go straight through without a consent screen and land in the portal. If they now reach the portal but see that they have no access, sign-in works and the remaining step is on your side. See How a contact actually gets in.

Microsoft error codes

Microsoft shows an AADSTS code on its error screen, and it tells the admin which step to look at.

While the partner’s IT team works on it

If the portal also offers Email as a login method, people at that partner can sign in with a one-time code sent to their work email in the meantime. Their access is the same either way, and they can switch to Microsoft sign-in once their admin has approved it. Login methods are set in Set up portal access.