Enable Microsoft Account Connections for Discovered

Some organizations restrict Microsoft account connections to third-party apps, which can block key Discovered features like Microsoft SSO, calendar sync, and email integration. This article is written for IT administrators. If your users cannot connect their Microsoft accounts to Discovered, please follow the steps below to enable access while maintaining enterprise security standards.

Overview

Some organizations restrict Microsoft account connections to third-party apps, which can block key Discovered features like Microsoft SSO, calendar sync, and email integration.

This article is written for IT administrators. If your users cannot connect their Microsoft accounts to Discovered, please follow the steps below to enable access while maintaining enterprise security standards.

Pre-Requisites 

Before you begin, make sure you have:

  • Global Administrator or Application Administrator rights in your Microsoft 365 tenant.
  • Access to the Azure Active Directory (Azure AD) portal.
  • A supported environment (Microsoft 365 / Azure AD).
  • Approval to grant delegated Microsoft Graph permissions for email and calendar access.

How to Enable Microsoft Account Connections

1. Enable user consent

  • Open the Azure portal.
  • Go to Azure Active Directory → Enterprise applications.
  • Select Manage → User settings.
  • Set Users can consent to apps accessing company data on their behalf to Yes.

2. Add the Discovered app to your directory

  • In Azure Active Directory, open Enterprise applications.
  • Click New application → Add an application from the gallery.
  • Search DiscoveredATS and follow the prompts to add it.

3. Assign users or groups

  • In Enterprise applications, select DiscoveredATS.
  • Open Users and groups → Add user/group.
  • Select the required users or groups and assign roles as needed.

4. Grant Admin Consent for Microsoft Graph Scopes

  • In the app’s settings, go to API permissions.
  • Click Add a permission → Microsoft Graph → Delegated permissions.
  • Select the following scopes:
  • Add manually, one by one.
  • Select the employees you want to include. You can:
    • Mail.Read – Allows Discovered to read candidate email threads in Outlook for context.
    • Mail.Send – Allows Discovered to send candidate communications on behalf of the user.
    • Calendars.Read – Enables viewing existing calendar events.
    • Calendars.ReadWrite – Allows scheduling, updating, or canceling interview events.
    • offline_access – Keeps the connection active without requiring users to re-authenticate frequently.
    • User.Read – Provides basic profile details for account verification.
  • Click Add permissions.
  • After adding, select Grant admin consent for [Tenant].
  • Confirm when prompted.

Security Notes

  • Discovered only requests delegated (user-scoped) permissions — no broad admin or application-wide rights.
  • Data access is limited strictly to the scopes listed above.
  • Passwords are never stored. Authentication is handled entirely through Microsoft OAuth.
  • Data is encrypted in transit and at rest, stored in U.S.-based servers.
  • Discovered adheres to enterprise-grade security and compliance standards, aligning with SOC 2 principles and global privacy frameworks such as GDPR and CCPA.

Troubleshooting 

If users still cannot connect after setup, check the following:

  • Consent option disabled: A Global Admin may need to allow user consent at the tenant level.
  • Conditional Access blocking login: Review Azure conditional access policies to ensure Discovered is not restricted.
  • DiscoveredATS not available in gallery: Add it as a custom app registration in Azure AD.
  • Permissions not applied: Verify that the listed Microsoft Graph scopes are granted with admin consent.

Why This Matters

  • Secure authentication via Microsoft OAuth.
  • Seamless scheduling by syncing Outlook/Teams calendars with Discovered.
  • Faster workflows with direct Microsoft email/calendar integration.
  • Least-privilege access using delegated Microsoft Graph permissions.

What Happens Next

  • Users can sign in with Microsoft (SSO).
  • Outlook/Teams calendars sync with Discovered for scheduling.

Users can send/receive candidate emails through their Microsoft accounts directly in Discovered.