Approve Astreo in Microsoft 365
Microsoft says "Need admin approval" when connecting? Then your IT has to approve Astreo once for the whole company. It takes a few minutes.
Approval granted. Your staff can now connect their Microsoft 365 mailbox in Astreo themselves. Anyone who tried before simply starts connecting again.
Approval was not granted. Usually the signed-in account lacks the required role, or the Microsoft dialog was cancelled. The roles that work are listed under For administrators.
In short: this is not an error in Astreo and not a problem with your computer. Your company has set up Microsoft so that apps with access to mailboxes must be approved by IT. That is a sensible protection. Approval is given once for the whole company; after that, everyone connects their own mailbox.
Why you see this message
Astreo reads and sends your mail through Microsoft's official interface. To do that, Astreo needs permission to access your mailbox. Who may grant that permission is decided by each company in the Microsoft Entra admin center:
- Users may consent themselves: the user confirms access and is connected right away.
- Managed by Microsoft or only low-risk permissions: many newer Microsoft 365 accounts are set up this way. Users may sign in themselves, but access to mail has to be approved by IT.
- Users may never consent: every app needs IT approval.
In the last two cases Microsoft shows the message "Need admin approval". This applies to every mail app, not just Astreo.
For staff: what to do now
- Send your IT department or IT provider the link to this page. The button below prepares a ready-made mail.
- Wait for confirmation that Astreo has been approved.
- Then connect your mailbox again: in Astreo under Connect mailbox → Microsoft.
Still on Microsoft's "Need admin approval" page? You can't get any further there. Use the link on that page to return to Astreo, or simply go back in your browser: Astreo then shows you a link you can send straight to your IT.
The message can also appear when you sign in with Microsoft. Until your IT has approved Astreo, sign in with your password or a login link; afterwards, signing in with Microsoft works too.
For administrators: approving Astreo
You need an account with one of these roles: Global Administrator, Cloud Application Administrator or Application Administrator.
Option 1: approval link (recommended)
Enter your company's domain. The link then takes you straight to your Microsoft 365 tenant. That helps if you look after several tenants, for example as an IT provider. Without a domain, Microsoft picks the tenant based on your sign-in.
Approval for: the tenant you sign in with
- Click Approve Astreo at Microsoft and sign in with your administrator account.
- Microsoft shows the app Astreo Mail, the publisher becom Systemhaus GmbH und Co KG with a blue verified badge, and the permissions. Click Accept.
- You return to this page and see the confirmation at the top. No mailbox is connected in the process, not even yours.
Option 2: in the Microsoft Entra admin center
This only works once a staff member has tried to connect their mailbox. Only then does Astreo appear in your list.
- Open entra.microsoft.com, then Identity → Applications → Enterprise applications.
- Search for Astreo Mail and open it.
- Permissions → Grant admin consent for [your company] and confirm.
What Astreo may do, and what not
All permissions are delegated. Astreo only acts on behalf of the user who signed in themselves, and only in that user's own mailbox. The approval gives Astreo no access to other mailboxes.
| Permission | What Astreo needs it for |
|---|---|
Mail.ReadWrite | read mail, mark it as read, move it to folders |
Mail.Send | send mail from Astreo |
User.Read | determine the user's sign-in address |
offline_access | sync the mailbox in the background without the user signing in again every time |
openid, email, profile | sign-in, including "Sign in with Microsoft" on Astreo |
Not requested, among others: calendar, contacts, files in OneDrive or SharePoint, Teams, your company directory, and permissions without a signed-in user (application permissions).
Who is behind Astreo
- Publisher: becom Systemhaus GmbH und Co KG, verified by Microsoft as publisher (blue badge in the consent dialog)
- App name at Microsoft: Astreo Mail
- Application ID:
45831fc2-9218-407d-8970-3cad3937580b - Publisher domain: becom.net (proof at becom.net/.well-known/…)
- Legal: Privacy policy, Data processing agreement, Legal notice
Restricting and revoking
Both are done in the Entra admin center under Enterprise applications → Astreo Mail:
- Allow only certain users: under Properties, set "Assignment required?" to Yes, then add the permitted people under Users and groups.
- Revoke approval: under Properties, delete the app. Connected mailboxes lose access and stop syncing.
Frequently asked questions
Does every user have to be approved individually?
No. The approval applies to the whole company. If you only want to allow certain users, restrict it as described above.
Approval has been granted, but the message still appears.
Start connecting in Astreo again, ideally in a new browser window. If the message still appears, check in the Entra admin center under Astreo Mail → Permissions whether the permissions are listed as granted. If "Assignment required?" is on, the user must also be assigned.
We are an IT provider looking after several companies.
Enter each company's domain above and grant approval per company. Or send the copied link to that company's administrator.
Who do I contact with questions?
Write to info@becom.net.