Benefits of granting calendar permissions
Granting the Calendars.ReadWrite permission to the absentify Calendars Permission app unlocks several key benefits:- Automated calendar synchronization: Absences created in absentify are automatically reflected in users’ Outlook calendars, removing the need for manual entry and ensuring all team members stay up-to-date.
- Enhanced visibility across Microsoft 365: Team members can view each other’s availability directly in Outlook and Microsoft Teams, making it easier to coordinate schedules, plan meetings, and manage team resources. Absences are displayed with color-coded entries, helping users quickly identify availability.
- Shared Outlook calendar updates (starts at the Mini plan level): With the Calendars.ReadWrite permission, absentify can populate shared Outlook calendars with absences for specific teams, departments, or user groups. This means that team leads or department managers can view absences collectively in shared calendars, not only within the absentify app but directly within Outlook. (Note: Group calendar synchronization does not require this permission — it uses only the
Group.ReadWrite.Allpermission granted to the separate absentify Group Calendar Permission app.)
Default functionality without granting permissions
If the Calendars.ReadWrite permission is not granted, absentify still offers basic calendar functionality:- iCal email invitations: Users who enable Calendar invitations can receive an iCal invitation for a new eligible request, approval, or meaningful date, time, or status change, according to the leave type’s timing rule. Absentify does not send a first invitation for an absence that has already ended unless calendar delivery for that request was authorized while the absence was still current or future; repair-only sync passes do not mass-mail old absences. Recurring series and representative copies follow the same timing. The user accepts or adds the event in their calendar app. This is an emailed calendar event, not a calendar subscription or feed. Enabling invitations does not by itself send first invitations for existing absences.
If a newly intended direct Outlook entry cannot be delivered and the user has enabled Calendar invitations, absentify can send an iCal invitation instead once calendar sync catches up. This fallback does not convert older calendar inventory into invitation emails.
When personal calendar entries are updated or removed
Entries already delivered are updated or cancelled when a meaningful request change requires it. This includes date or time changes, approval and status changes, privacy corrections, cancellations, deletions, and changes to an approved representative.- A cancellation or decline removes the delivered entry. Canceling one day of a recurring series does not remove the other days.
- Older iCal series and per-day invitations from earlier recurring synchronization can still receive necessary request updates and cancellations.
- Turning Outlook calendar synchronization off, changing the leave type Calendar Synchronization option, or changing a user’s email address does not start a bulk cancellation and resend. New request actions use the current destination and settings.
- Cosmetic profile, language, leave-type name, or subject changes do not by themselves send iCal updates for existing absences. The latest display details are included with the next necessary request update.
How absentify uses the calendar permission
To ensure transparency and trust, here’s how absentify uses the Calendars.ReadWrite permission in the absentify Calendars Permission app:- Limited scope of access: This permission is used exclusively to create, update, or delete calendar entries related to absences. We do not read any other calendar data or events.
- Absence reason: If a user enters a reason, absentify includes it in the event description on that user’s personal calendar. Shared Outlook, group, and Teams group calendar events include the reason only when reason visibility is unrestricted and the leave type is not private.
- Data storage: When an absence entry is created, we save only the ID of the Outlook calendar event after it has been created. This ID allows us to modify or delete the entry if the absence is canceled or updated.
- No data extraction: absentify does not access or extract information from other calendar entries, ensuring that your users’ personal calendar data remains private and untouched.
Security and data protection
Our commitment to data security includes the following measures:- ISO 27001 certification: absentify is ISO 27001 certified, which demonstrates compliance with stringent international standards for information security management.
- Microsoft 365 App Certification: The absentify Calendars Permission app has achieved Microsoft 365 App Certification, confirming adherence to Microsoft’s strict security and compliance standards. This certification assures that absentify follows best practices in data handling and security.
- Secure key management in Azure Vault: The application secret used for calendar synchronization is securely stored in an Azure Key Vault in North Europe. Only authorized personnel at absentify GmbH have access to this application secret; no developers or other team members can access it. There is no external copy of the key.
Granting permissions to the absentify Calendars Permission app
Grant Calendars.ReadWrite for the absentify Calendars Permission app from absentify. Do not open a public Microsoft consent URL. Go to Settings > Microsoft and turn on the feature. If the Microsoft permission is missing, Permissions Required opens. If someone sent you a consent link from that page, open that link instead. If you are a tenant administrator, select I am a Tenant Administrator, then Grant Permissions Now. You need a linked Microsoft account. Microsoft opens so you can grant the permission. If you are not a tenant administrator, select I am not a Tenant Administrator. Select Open Pre-Filled Email or Copy Consent Link, then send that request to your IT team. On the web, Grant Permissions Now takes you to Microsoft. You leave absentify and return to Settings > Microsoft with a result banner. If Microsoft confirmed consent but the permission is not visible to absentify yet, Settings > Microsoft shows Waiting for Microsoft… and Microsoft confirmed the consent. The permission usually shows up within a minute; this page checks every few seconds. Select Check now. In Microsoft Teams or SharePoint, Microsoft opens in another window. Settings > Microsoft then shows Waiting for Microsoft… and Grant the permission in the window that opened, then come back here. Select I have granted it. A banner on Settings > Microsoft reports the result after you return from the web. Copied or emailed links, and the window in Microsoft Teams or SharePoint, open a result page instead. That page may show Permission granted, Almost there, Permission was not granted, Wrong Microsoft 365 tenant, This link is no longer valid, or Something went wrong. If the feature was switched off in absentify, you see Permission was not activated. If you close Microsoft before consent, or if consent is declined, nothing changes. Granting the permission requires a Microsoft 365 administrator. A copied or emailed link belongs to your workspace and expires after 14 days. A request you start in the app expires after 15 minutes. Old public Microsoft consent URLs fail with This link is no longer valid. Start again from absentify. If your tenant later revokes the permission, the row shows a warning and Grant again. After a successful grant, Outlook calendar synchronization must be on in Settings > Microsoft. If you started from that page, a successful grant turns it on. Without it, absences stay on iCal email invitations.Revoking permissions
If you need to revoke the granted permissions:- Access Azure Active Directory: Sign in to the Azure portal with your administrator account.
- Navigate to Enterprise applications: In the left-hand menu, go to Azure Active Directory > Enterprise applications.
- Select absentify Calendars Permission: Locate and select the absentify Calendars Permission app from the list.
- Manage permissions: Under Permissions, review and revoke permissions as needed.