Benefits of granting group calendar synchronization permissions
Granting the Directory.Read.All and Group.ReadWrite.All permissions to the absentify Group Calendar Permission app offers significant advantages for your organization:- Automated absence visibility: Automatically adds user absences to relevant group calendars, making it easier for team members to see who is out and when.
- Teams calendar integration: Ensures that absences are visible in Microsoft Teams calendar views, improving team coordination and planning.
- Streamlined calendar management: Reduces manual effort by updating group calendars when absences change, and by removing events when the request is canceled or no longer matches the connection.
Default functionality without permissions
If the Directory.Read.All and Group.ReadWrite.All permissions are not granted, absentify’s Group Calendar Synchronization features are unavailable. Without these permissions:- Manual calendar updates: Team members must manually add absences to group calendars or rely on other communication methods to stay informed about team availability.
- No Teams calendar visibility: Absences will not appear in Microsoft Teams calendar views, potentially leading to scheduling conflicts or miscommunication.
- Increased administrative workload: HR or managers may need to manually communicate absences or update shared calendars, increasing administrative burden.
How absentify uses the Directory and Group permissions
To promote transparency and trust, here’s how absentify uses the Directory.Read.All and Group.ReadWrite.All permissions in the absentify Group Calendar Permission app:- Directory access: Directory.Read.All allows absentify to access group and organizational information necessary to identify the appropriate group calendars for absence synchronization.
- Group calendar management: Group.ReadWrite.All (Application) permits absentify to add, update, and remove absence events in group calendars when absences change or no longer belong on that calendar.
- Teams calendar support: Group.ReadWrite.All (Delegated) is required for Teams calendar functionality. It ensures that absences appear correctly in Microsoft Teams calendar views, where group calendars are accessed on behalf of users.
- Secure storage: All calendar synchronization data is stored in absentify’s database to maintain application performance and reduce reliance on Microsoft API calls. Data is stored securely in Azure North Europe, adhering to GDPR requirements. Access to this data is strictly limited to authorized personnel at absentify GmbH, with no access for developers or external parties.
Security and data protection
absentify adheres to strict security protocols to protect your organization’s data:- ISO 27001 certification: absentify is ISO 27001 certified, confirming compliance with international standards for information security management.
- Microsoft 365 App Certification: The absentify Group Calendar Permission app has achieved Microsoft 365 App Certification, meeting Microsoft’s requirements for security, privacy, and compliance. This certification assures that absentify follows best practices in data handling.
- Controlled access: Access secrets and permissions required for group calendar synchronization are securely stored in an Azure Key Vault, restricted to necessary personnel only. No developers or members of other departments can access production data, ensuring full data security.
Enabling group calendar synchronization
Grant Group.ReadWrite.All for the absentify Group Calendar Permission app from absentify. Do not open a public Microsoft consent URL. Go to Settings > Microsoft and turn on the feature. If the Microsoft permission is missing, Permissions Required opens. If someone sent you a consent link from that page, open that link instead. If you are a tenant administrator, select I am a Tenant Administrator, then Grant Permissions Now. You need a linked Microsoft account. Microsoft opens so you can grant the permission. If you are not a tenant administrator, select I am not a Tenant Administrator. Select Open Pre-Filled Email or Copy Consent Link, then send that request to your IT team. On the web, Grant Permissions Now takes you to Microsoft. You leave absentify and return to Settings > Microsoft with a result banner. If Microsoft confirmed consent but the permission is not visible to absentify yet, Settings > Microsoft shows Waiting for Microsoft… and Microsoft confirmed the consent. The permission usually shows up within a minute; this page checks every few seconds. Select Check now. In Microsoft Teams or SharePoint, Microsoft opens in another window. Settings > Microsoft then shows Waiting for Microsoft… and Grant the permission in the window that opened, then come back here. Select I have granted it. A banner on Settings > Microsoft reports the result after you return from the web. Copied or emailed links, and the window in Microsoft Teams or SharePoint, open a result page instead. That page may show Permission granted, Almost there, Permission was not granted, Wrong Microsoft 365 tenant, This link is no longer valid, or Something went wrong. If the feature was switched off in absentify, you see Permission was not activated. If you close Microsoft before consent, or if consent is declined, nothing changes. Granting the permission requires a Microsoft 365 administrator. A copied or emailed link belongs to your workspace and expires after 14 days. A request you start in the app expires after 15 minutes. Old public Microsoft consent URLs fail with This link is no longer valid. Start again from absentify. If your tenant later revokes the permission, the row shows a warning and Grant again. Group Calendar Synchronization must be on in Settings > Microsoft. If you started from that page, a successful grant turns it on. Then go to Settings > Integrations to connect group calendars.Key features of group calendar synchronization
With the Group Calendar integration enabled, absentify provides several key features:- Automatic absence events: Automatically create calendar events in group calendars when absences match the connection.
- Updates and removals: Update group calendar events when absences change. Remove them when the request is canceled or declined, or when it no longer matches the group calendar connection. Existing group events stay if you only change the leave type’s personal Calendar options.
- Teams integration: Ensure absences are visible in Microsoft Teams calendar views for better team coordination.
- Department-specific calendars: Sync absences to department-specific group calendars based on user assignments.
Revoking permissions
If you need to revoke the Directory.Read.All or Group.ReadWrite.All permissions for the absentify Group Calendar Permission app, follow these steps:- Access Azure Active Directory: Sign in to the Azure portal with your Microsoft 365 administrator account.
- Navigate to Enterprise applications: In the left-hand menu, go to Azure Active Directory > Enterprise applications.
- Find and select absentify Group Calendar Permission: Locate the absentify Group Calendar Permission app (App ID: aa06e0d6-dd66-4d79-9ec5-660a87afbfdd) in your list of applications.
- Manage permissions: Go to the Permissions section and select Directory.Read.All and Group.ReadWrite.All to revoke absentify’s access to group and directory data.