Microsoft approval for administrators
Note: This page describes the one-time admin consent. It only needs to be carried out once per organization. If an individual user has problems with their Microsoft 365 integration (e.g. emails, calendar, or Teams no longer work), this is usually not due to the admin consent, but to the user’s personal integration. In that case see Set up tool: Connecting Microsoft 365.
To connect 9brains with your Microsoft 365, a one-time approval by an administrator in your company is required. This guide walks you through the process.
What is being enabled?
Section titled “What is being enabled?”9brains offers three Microsoft integrations:
- Sign in with Microsoft: your employees can sign in to 9brains with their Microsoft 365 account, once they have been invited to 9brains
- Microsoft 365 integration: 9brains can access emails, calendar, OneDrive, Teams, and other Microsoft 365 services to support your employees in their daily work
- Data sources (RAG): 9brains can index SharePoint libraries so that your company knowledge becomes searchable in the chat
Prerequisites
Section titled “Prerequisites”- Your company uses Microsoft 365 Business (no personal Microsoft accounts)
- The approval must be granted by a Global Administrator or Application Administrator of your Microsoft tenant
Important: the approval works exclusively through the three links on this page. You cannot find and add the 9brains apps in the Azure Portal via Enterprise applications → + New application. That search only covers the public Microsoft app catalog, and 9brains is deliberately not listed there. As long as you have not granted the approval, the apps do not exist in your Microsoft tenant at all, so no search will turn them up. They only appear under Enterprise applications after you click the links below.
Step 1: Enable sign in with Microsoft
Section titled “Step 1: Enable sign in with Microsoft”Click the following link and sign in with your administrator account:
This step grants the following permissions:
- View email address
- Sign in users
- View basic profile
- Read user profile
Review the requested permissions and click “Accept”.
Wait a moment after granting access: After you click “Accept”, you land on a confirmation page. It takes one to two minutes for Microsoft to fully activate the access. Wait that short while before your first users sign in. If the first sign in does not work yet, start it again after a minute using a fresh sign-in link instead of reloading the error page.
This approval does not create any user accounts. It only allows your organization to use the “Sign in with Microsoft” button in the first place. Only people who already have a 9brains account can sign in that way. Everybody else you invite under Settings → Users, and only then does their Microsoft sign-in work. The address matters here: it has to be exactly the one Microsoft signs the person in with, which is not always the one they receive their email under.
Step 2: Enable Microsoft 365 integration
Section titled “Step 2: Enable Microsoft 365 integration”Click the following link and sign in again with your administrator account:
Enable Microsoft 365 integration
This step grants the following permissions:
- Calendar (read/write, including shared calendars)
- Emails (read/write/send, including shared mailboxes)
- OneDrive files (read/write)
- OneNote (read/create)
- Tasks & Planner (read/write)
- Teams & channels (read/write)
- SharePoint sites (read/write)
- Contacts (read/write)
Review the requested permissions and click “Accept”.
Step 3: Enable data sources (RAG)
Section titled “Step 3: Enable data sources (RAG)”Note: This step is only required if your company wants to use SharePoint libraries as a data source for the AI knowledge base. For the plain Microsoft 365 integration (emails, calendar, Teams), steps 1 and 2 are sufficient.
Click the following link and sign in again with your administrator account:
This step grants the following permissions:
- Read SharePoint sites and libraries (for indexing documents)
- Read files (for processing and searching content)
- Read group memberships (for permission-based access control)
Review the requested permissions and click “Accept”.
Step 4: Verify approval (optional)
Section titled “Step 4: Verify approval (optional)”You can confirm a successful approval in your Azure Portal:
- Open portal.azure.com
- Navigate to Microsoft Entra ID → Enterprise applications
- Search for “9brains”
- All three apps should appear there with the status “Granted”: 9brains SSO, 9brains M365 and 9brains Sharepoint Crawler
Nothing found? Two possible reasons. Either the approval has not been granted yet, in which case the app does not exist in your tenant and you start with step 1. Or your organization granted the approval before May 2026, in which case the apps still carry their former names Octopus SSO, Octopus M365 and Octopus Sharepoint Crawler in your tenant. Microsoft does not apply a later rename retroactively. In that case, search for “Octopus”. The name makes no difference to how the apps work, there is nothing you need to do.
Restrict access to specific users (optional)
Section titled “Restrict access to specific users (optional)”By default, all users in your company can use 9brains. If you want to restrict access:
- Open portal.azure.com
- Navigate to Microsoft Entra ID → Enterprise applications
- Search for “9brains” (for approvals granted before May 2026: “Octopus”) and open the respective app
- Go to Properties and set “Assignment required?” to Yes
- Under Users and groups you can then add specific users or groups
Next step: users set up their own integration
Section titled “Next step: users set up their own integration”The administrator approval is only the prerequisite. After that, each user must set up their personal Microsoft 365 integration themselves:
- Go to Settings → System integrations
- Click ”+ Tool” → “From template” → “Microsoft 365”
- A sign-in popup opens: sign in with your own Microsoft account and grant permission
Only after this step can the AI access the user’s emails, calendar, OneDrive, Teams, and other Microsoft 365 services. Each user has their own personal connection.
Detailed instructions: Set up tool: Connecting Microsoft 365
Frequently asked questions
Section titled “Frequently asked questions”I cannot find the 9brains apps in the Azure Portal
Section titled “I cannot find the 9brains apps in the Azure Portal”This is the most common stumbling block. The 9brains apps cannot be found and added via Enterprise applications → + New application. That search only shows apps from the public Microsoft catalog, and 9brains is deliberately not listed there. The only route is the three approval links in steps 1 to 3 of this guide. After you click them, Microsoft creates the app in your tenant automatically, and from then on it is findable under Enterprise applications.
The apps in my tenant are named “Octopus”, not “9brains”
Section titled “The apps in my tenant are named “Octopus”, not “9brains””That is expected and not an error. 9brains was called “Octopus AI” until May 2026. Microsoft freezes an app’s name at the moment you grant the approval and does not apply later renames. If your organization granted the approval before May 2026, you still see the old names. Functionality and permissions are identical, there is nothing to change.
A user cannot use Microsoft 365 (emails, calendar, Teams are missing)
Section titled “A user cannot use Microsoft 365 (emails, calendar, Teams are missing)”First check whether the user has their own Microsoft 365 integration under Settings → System integrations. If not, they must set this up themselves (see “Next step” above). Admin consent alone is not enough, it only grants the organization-wide permission, but each user must additionally connect personally.
Users see the message “Administrator approval required”
Section titled “Users see the message “Administrator approval required””The approval by an administrator has not yet been granted. Please carry out steps 1 to 3 of this guide.
A user sees “The account … hasn’t been activated in 9brains yet”
Section titled “A user sees “The account … hasn’t been activated in 9brains yet””This message means exactly one thing: there is no account here under the address shown in the message. The administrator approval does not change that, and waiting does not help, because no account appears by itself.
There are two possible causes. Either the person has not been invited at all, in which case you do so under Settings → Users. Or they were invited under a different address than the one Microsoft reports, which is the more common case. Many Microsoft 365 accounts have a sign-in name such as m.doe@company.com alongside an alias such as max.doe@company.com under which the person receives their email. For signing in to 9brains, only the former counts. So invite the person under exactly the address shown in the error message.
9brains has no queue of sign-in attempts for you to approve. The route is always the invitation.
Sign-in does not work after approval
Section titled “Sign-in does not work after approval”- Check the account: by far the most common reason. Is the person listed under Settings → Users, under exactly the address they sign in with? See the question right above
- Use an incognito window: open 9brains in an InPrivate or incognito window to rule out browser cache issues
- Wait a moment: propagating the permissions can take a few minutes
- Check permissions: in the Azure Portal under Enterprise applications → 9brains app → Permissions, verify that all permissions have the status “Granted”
- Grant approval again: in the respective enterprise application under Permissions, click “Grant admin consent for [your tenant]”
Any other questions?
Section titled “Any other questions?”Feel free to contact us at support@9brains.de, we are happy to help with the setup.