Sign-in and consent troubleshooting
Work through the symptom that matches what the user sees; each fix is self-contained.
Fix “Your organization requires admin approval”
Section titled “Fix “Your organization requires admin approval””Symptom: sign-in (or a feature’s permission prompt) stops with Your organization requires admin approval — “A Microsoft 365 admin needs to approve Orbit once for your organization.”
Cause: your tenant’s Entra policy blocks users from consenting to app permissions themselves, so a Microsoft 365 admin must approve Orbit once.
Fix:
- Select Copy approval link or Email your admin and send the link to a Microsoft 365 admin. (If you are the admin, select Open Microsoft approval.)
- The admin opens the link, signs in, and accepts — the flow is click-only, with no configuration to fill in. The link follows the pattern
https://login.microsoftonline.com/{tenant}/v2.0/adminconsent?client_id=.... - Sign in again.
The deploy guide lists exactly which permissions the approval covers. User.Read.All (people search) requires admin consent in every tenant, so expect this flow at least once even in tenants that allow user consent.
📷 Screenshot here: the “Your organization requires admin approval” dialog with the Copy approval link and Email your admin buttons visible.
Fix a blocked Microsoft consent window
Section titled “Fix a blocked Microsoft consent window”Symptom: a feature asks for a new permission, but nothing opens — Orbit shows Your browser blocked the Microsoft window.
Cause: Orbit asks for permissions just in time in a Microsoft popup, and your browser’s popup blocker stopped it.
Fix: select Continue in a new page. The consent finishes in a full browser page and returns you to Orbit.
Fix an empty Members list
Section titled “Fix an empty Members list”Symptom: a workspace’s Members section asks for consent or shows Manage in SharePoint instead of the roster.
Cause: listing members needs one-time SharePoint read consent (AllSites.Read) — a separate, SharePoint-resource approval. If SharePoint itself does not let your account view the site’s membership, Orbit cannot list it either.
Fix: approve the SharePoint consent when prompted. If the roster stays unavailable, manage members in SharePoint via the Manage in SharePoint link — SharePoint remains the source of truth for site membership.
Fix sign-in with a personal Microsoft account
Section titled “Fix sign-in with a personal Microsoft account”Symptom: sign-in with an @outlook.com or other personal Microsoft account fails.
Cause: Orbit requires a Microsoft 365 work or school account; personal Microsoft accounts are not supported.
Fix: sign in with your organization account.
Fix conditional access blocks
Section titled “Fix conditional access blocks”Symptom: the Microsoft sign-in window itself shows an error naming your organization’s access requirements (device, location, or app policy).
Cause: your tenant’s conditional access policy blocked the sign-in — this happens inside Microsoft’s sign-in, before Orbit runs.
Fix: sign in from a device and network that satisfy the policy, or ask your IT team to adjust the policy for Orbit.
Fix Teams sign-in
Section titled “Fix Teams sign-in”Symptom: the Orbit Wiki tab shows Teams sign-in is required — “Teams could not silently provide an Orbit sign-in token.”
Fix: select Sign in with Teams, or close and reopen the Orbit tab. If Teams signs you in but Orbit then reports missing Graph permissions, your tenant needs the admin approval flow above.
Fix “stuck signed out” in Teams
Section titled “Fix “stuck signed out” in Teams”Symptom: after signing out inside Teams, Orbit never signs back in on its own.
Cause: this is deliberate. Orbit cannot end your Microsoft session from inside a Teams tab, so after Sign out it remembers your choice and stops restoring the session automatically — even across Teams restarts.
Fix: select Sign in with Teams when you want back in.
Still stuck? Contact support.