🔒 New browser security hardening is live to help defend against AI-driven attacks. Learn more

Login with Microsoft Blocked by Admin Approval

Prev Next

This document explains what to do when signing in with the 'Login with Microsoft' option on the eSHARE login page is blocked by a Microsoft admin approval screen. This is intended for end users signing in to the eSHARE platform. The following steps will be reviewed:

SCOPE:

eSHARE supports two ways to sign in: 'Login with Microsoft', which uses OpenID to bridge your Microsoft identity, and an eSHARE account, accessed with the 'Login with us' button or created with the 'Register with us' option. This document covers what to do when the Microsoft option is blocked by your organization.

Why This Happens

'Login with Microsoft' works by bridging your identity through OpenID, using an application called 'e-Share OpenID' that must be granted permission in your organization's Microsoft Entra tenant. Some organizations restrict which applications users are allowed to consent to on their own. If your organization has not already granted permission to the e-Share OpenID application, and you are not allowed to grant that permission yourself, Microsoft will stop the sign-in and ask for admin approval instead of completing the login.

Note:

Whether you see a full block or a screen offering to request approval depends on your organization's Microsoft Entra admin consent settings. eSHARE does not control which screen Microsoft shows.

Identifying the Screens

  1. On the eSHARE login page, selecting 'Login with Microsoft' redirects you to Microsoft to sign in.

eSHARE login page showing the Login with Microsoft and Login with us buttons

  1. If your organization has not granted any permission to the e-Share OpenID application, you will see a screen titled 'Need admin approval'. This screen only offers to sign in with a different account or return to eSHARE without granting consent. There is no way to proceed as the current user.

Microsoft Need admin approval screen for the e-Share OpenID application

  1. If your organization allows requesting approval, you will instead see a screen titled 'Approval required', listing the permissions requested and a 'Request approval' button. This button stays disabled until a justification is entered, and even then it only sends a request. It does not sign you in immediately.

Microsoft Approval required screen with a justification field and disabled Request approval button

Signing In with eSHARE Account

In either case, you can avoid waiting on IT by using an eSHARE account instead of 'Login with Microsoft'. This is the recommended path, since it lets you proceed immediately.

  1. Return to the eSHARE login page. If you were shown the 'Need admin approval' screen, select 'Return to the application without granting consent'; if you were shown the 'Approval required' screen, select 'Cancel'.

  2. If you already have an eSHARE account, select 'Login with us' and sign in with your eSHARE credentials.

  3. If you do not have an eSHARE account yet, select 'Register with us' to create one.

  4. Once you are signed in, you will be able to access your trusted shares without needing any Microsoft admin approval.

REQUIREMENT:

If you would still prefer to sign in with Microsoft, ask your IT admin to grant admin consent for the 'e-Share OpenID' application in Microsoft Entra. This is a valid option, but it will take longer than signing in with an eSHARE account directly.