Why these permissions matter
With Schedule.ReadWrite.All and Group.Read.All, organizations that plan work in Microsoft Teams Shifts get:- Time off in the timeline: Approved absences in absentify appear in the relevant Shifts schedule, so shift planners and colleagues see who is off without leaving Teams.
- No double entry: Managers do not have to create matching time-off entries in Shifts after they approve an absence in absentify.
- A schedule that stays current: absentify creates, updates, and removes time-off entries when absences change.
What happens without the permissions
If Schedule.ReadWrite.All and Group.Read.All are not granted, Shifts synchronization is unavailable:- Shift planners must create and maintain time-off entries in Shifts by hand.
- Date changes, cancellations, and declined requests in absentify are not reflected in Shifts unless someone updates Shifts manually.
How absentify uses the permissions
- Schedule.ReadWrite.All lets absentify read whether a team has Shifts switched on, manage time-off reasons, and create, update, or delete time-off entries for approved absences.
- Group.Read.All lets absentify list the Microsoft Teams in your tenant so an administrator can choose which team’s Shifts schedule to connect. No groups are changed. Microsoft’s application permission is broader: it can read properties and memberships for all groups, and for Microsoft 365 groups it also covers group content such as conversations, files, and notes. absentify does not read that group content.
- Storage: Synchronization metadata (time-off IDs and sync status) is stored in absentify’s database in Azure North Europe, in line with GDPR. Access is restricted to authorized personnel at absentify GmbH.
Security and data protection
- ISO 27001 certification: absentify is ISO 27001 certified.
- Microsoft 365 App Certification: The app meets Microsoft’s requirements for security, privacy, and compliance.
- Controlled access: Secrets for Shifts synchronization are stored in an Azure Key Vault and limited to the people who need them.
Enable Shifts synchronization
Grant Schedule.ReadWrite.All and Group.Read.All for the absentify Shifts Permission app from absentify. Do not open a public Microsoft consent URL. Go to Settings > Microsoft and turn on the feature. If the Microsoft permission is missing, Permissions Required opens. If someone sent you a consent link from that page, open that link instead. If you are a tenant administrator, select I am a Tenant Administrator, then Grant Permissions Now. You need a linked Microsoft account. Microsoft opens so you can grant the permission. If you are not a tenant administrator, select I am not a Tenant Administrator. Select Open Pre-Filled Email or Copy Consent Link, then send that request to your IT team. On the web, Grant Permissions Now takes you to Microsoft. You leave absentify and return to Settings > Microsoft with a result banner. If Microsoft confirmed consent but the permission is not visible to absentify yet, Settings > Microsoft shows Waiting for Microsoft… and Microsoft confirmed the consent. The permission usually shows up within a minute; this page checks every few seconds. Select Check now. In Microsoft Teams or SharePoint, Microsoft opens in another window. Settings > Microsoft then shows Waiting for Microsoft… and Grant the permission in the window that opened, then come back here. Select I have granted it. A banner on Settings > Microsoft reports the result after you return from the web. Copied or emailed links, and the window in Microsoft Teams or SharePoint, open a result page instead. That page may show Permission granted, Almost there, Permission was not granted, Wrong Microsoft 365 tenant, This link is no longer valid, or Something went wrong. If the feature was switched off in absentify, you see Permission was not activated. If you close Microsoft before consent, or if consent is declined, nothing changes. Granting the permission requires a Microsoft 365 administrator. A copied or emailed link belongs to your workspace and expires after 14 days. A request you start in the app expires after 15 minutes. Old public Microsoft consent URLs fail with This link is no longer valid. Start again from absentify. If your tenant later revokes the permission, the row shows a warning and Grant again. Microsoft Shifts synchronization must be on in Settings > Microsoft. If you started from that page, a successful grant turns it on. absentify checks that bothSchedule.ReadWrite.All and Group.Read.All are granted.
Then go to Settings > Integrations > Microsoft Shifts. Connect a team opens a dedicated page where you choose the Microsoft Team, departments, and leave types. See the Microsoft Shifts integration guide.
What the integration does
- Writes time-off entries when absences are approved.
- Updates or removes those entries when an absence is changed, canceled, declined, or deleted.
- Maps each selected leave type to a Shifts time-off reason. The display name is configurable. The color follows the leave type color in absentify.
- Uses the user’s absentify working schedule for the time-off period, not their Shifts shift assignments.
Plan requirements
Microsoft Shifts synchronization is available on the Essentials and Plus plans.Revoke permissions
- Sign in to the Microsoft Entra admin center with a Microsoft 365 administrator account.
- Go to Identity > Applications > Enterprise applications.
- Open the absentify Shifts Permission app.
- In Permissions, revoke
Schedule.ReadWrite.AllandGroup.Read.All, or delete the app’s service principal.