Microsoft SSO for Organizations

If your employees use Microsoft 365 work accounts, an IT administrator may need to approve Bümpis before they can sign in. This guide explains how to enable Microsoft SSO for your organization.

Why is admin approval required?

Many organizations restrict which third-party applications can access employee accounts. This is a security feature. When an employee tries to sign in to Bümpis with their work Microsoft account, they may see an error like "Need admin approval" or "AADSTS65001".

Option 1: Grant Admin Consent (Recommended)

The simplest way to enable Bümpis for your organization is to grant admin consent. This allows all users in your organization to sign in.

1

Sign in to Azure Portal

Go to portal.azure.com as a Global Administrator or Application Administrator.

2

Navigate to Enterprise Applications

Go to Azure Active DirectoryEnterprise ApplicationsAll Applications

3

Find Bümpis

Search for "Bümpis" in the application list. If it doesn't appear, it will be added automatically after the first user attempts to sign in.

4

Grant Admin Consent

Click on the Bümpis application, go to Permissions in the left sidebar, and click Grant admin consent for [Your Organization]. Review the permissions and click Accept.

Option 2: Assign Specific Users

If your organization requires explicit user assignment to applications:

  1. In the Bümpis Enterprise Application settings
  2. Go to Users and groups
  3. Click Add user/group
  4. Select the users or groups who should have access

Option 3: Enable User Consent

If you want to allow users to consent to applications themselves:

  1. Go to Azure Active DirectoryEnterprise ApplicationsConsent and permissions
  2. Under "User consent settings", choose one of:
    • Allow user consent for apps (least restrictive)
    • Allow user consent for apps from verified publishers

Common Error Messages

ErrorSolution
AADSTS65001User needs admin approval. Grant admin consent (Option 1).
AADSTS50105User not assigned to the app. Assign the user (Option 2).
Consent_RequiredAdmin consent is required. Grant admin consent (Option 1).
Need admin approvalOrganization blocks user consent. Grant admin consent (Option 1).

Permissions Bümpis Requests

Bümpis requests minimal, read-only permissions:

  • User.Read — Read user's basic profile
  • email — Access user's email address
  • profile — Access user's name and profile picture
  • openid — Standard OpenID Connect sign-in

These permissions do not allow Bümpis to access emails, calendars, files, or other organizational data. We only read basic profile information for sign-in purposes.

Need help setting this up?

Our team can assist with enterprise SSO configuration.

Contact Support