Skip to content

Tenant-wide admin consent

One approval from a Global Administrator activates Dockli for your whole tenant — and spares every user from their own consent prompt. Here's exactly what it does and how to grant it.

Last updated: July 2026

Dockli is activated by a single, tenant-wide admin consent in Microsoft Entra. This is the trigger that binds your tenant to your order and flips your licence to Active. Until it’s granted, nobody in your organization can use Dockli; once it’s granted, everyone can sign in with no approval prompt of their own.

When a Microsoft 365 app needs to call Microsoft Graph on behalf of your users, someone has to approve the permissions it requests. There are two ways that can happen:

  • Per-user consent — each user is prompted to approve the app the first time they sign in.
  • Tenant-wide admin consent — an administrator approves the app once, for the entire organization, so no individual user is ever prompted.

Dockli uses the second model. Your administrator approves it one time, and that approval covers every current and future user in the tenant.

Dockli acts only as the signed-in user

Granting consent does not give Dockli standing access to your files. Dockli only ever acts as the signed-in user, using that person’s own Microsoft 365 permissions. Consent simply removes the per-user approval prompt. For the full list of permissions requested, see Permissions and scopes.

Who can grant it

Only a Global Administrator can grant tenant-wide admin consent. A regular user — even a licensed Dockli user — cannot approve it, and neither can most delegated admin roles. If the person opening the consent link isn’t a Global Administrator, Microsoft will block the approval and Dockli stays inactive.

The approval flow

The Dockli team sends your administrator a branded email — subject “Action needed: approve Dockli for your organization” — containing the consent link. The exact sequence:

  1. Open the emailed link. Your Global Administrator clicks Grant consent to Dockli in the email (or pastes the link into a browser). It opens Microsoft’s own sign-in and consent page at login.microsoftonline.com.
  2. Sign in as a Global Administrator. Microsoft authenticates the admin against your tenant.
  3. Review the permissions. Microsoft shows the exact Microsoft Graph permissions Dockli requests. The admin reviews them before approving — this is Microsoft’s page, not Dockli’s.
  4. Approve. Approving grants the permissions for the whole tenant. Microsoft redirects back to a Dockli success page confirming “Your organization is approved” and showing your bound tenant ID.
  5. Tenant bound, licence Active. Behind the scenes, the approval binds your tenant to your order and switches your licence to Active. The same success page offers a Create access group button so the admin can set up team access straight away — see Access groups and seats.

Lost the email?

The consent link can be re-issued and re-sent. Contact the Dockli team and they will send a fresh approval link to your admin. The link only works until consent is granted, after which it’s no longer needed.

Why users then see no prompt

Because consent was granted for the entire tenant, Microsoft already trusts Dockli on behalf of every user. When a user signs in, there is nothing left to approve — they authenticate with their Microsoft 365 account and go straight in. This is why the model scales: you approve once, not once per person.

The “needs admin approval” experience

If a user tries to sign in before consent has been granted (or if approval didn’t complete), Microsoft blocks them with a message along the lines of “Need admin approval” — telling them an administrator must approve the app before they can use it. This is expected and harmless; it simply means Step 1 of the rollout hasn’t finished yet.

To resolve it, have your Global Administrator complete the consent flow above. Once the tenant is bound, affected users can sign in immediately with no further action.

Approval didn't complete?

If the approval page reports that consent was not completed, the most common cause is that the person who opened the link was not a Global Administrator. Have a Global Administrator open the link again and approve. More diagnostics are in Troubleshooting sign-in and consent.

Where to go next

Still stuck? Email support@dockli.io — a human replies within one business day. Or book a demo.