Microsoft Account Login Failed

Microsoft Account Login Failed

"You can't access this application" when authenticating as service account

Requires access to organizational resources that only administrators can authorize. Please ask the administrator to authorize the use of this application before you can use it.


Why does this happen?

The most common cause is users not having permission to complete OAuth consent screens for applications, unless they are an admin within your Office 365 tenant. Enterprise apps like Gaia Workspace use OAuth as a more secure way to authorize scoped access to your Office 365 tenant calendars vs. username and password.


Solution 1

Agree after logging into Gaia Workspace using an administrator account to review permissions.



Solution 2

How can I allow the service account to authenticate?

The easiest way to allow your service account to connect is to enable user access to Enterprise apps. From your Office 365 Admin portal, go to Admin Centers > Azure AD > Users and Groups > User Settings then make sure "Users can consent to apps accessing company data on their behalf" is enabled.










Perhaps after logging into Azure, you can directly access this link address

https://aad.portal.azure.com/?l=en.en-us#view/Microsoft_AAD_IAM/ConsentPoliciesMenuBlade/~/UserSettings

 

 

 

Do I need to leave this setting enabled for everyone?

Once you enable this setting, you should be able to complete the authentication process with the service account in Gaia Workspace, and users signing in via Office 365 SSO. If you do not plan on using Office 365 for SSO in Gaia Workspace, you can disable this setting once the service account is connected successfully.

Pro Tip

Comfortable with advanced configurations in Office 365? You can also create a group policy to override this setting for specific users (i.e. the Gaia Workspace service account) instead of toggling tenant-wide.

References