8b0be019-bc8c-43c0-ac17-5114e604a9f8), with the delegated permissions Calendars.ReadWrite and offline_access.
Work location
Why these permissions matter
WithCalendars.ReadWrite and offline_access, organizations that use Microsoft work location get:
- Remote on home office days: Approved full-day home office in absentify appears as Remote on the Outlook calendar and the Teams people card.
- No double entry: Users do not have to set those days to Remote in Outlook after they request home office in absentify.
- Away stays on the calendar sync: Vacation and other leave still become Away through calendar entries. Work location sync does not write those days.
What happens without the permissions
IfCalendars.ReadWrite and offline_access are not granted, work location sync is unavailable:
- Home office days in absentify do not change work location in Teams or Outlook.
- Users who want Remote on those days must set it in Outlook themselves.
How absentify uses the permissions
Calendars.ReadWritelets absentify set a user’s Microsoft work location to Remote for approved full-day home office, and set it back when the request no longer covers that day.offline_accesskeeps that user’s connection available so absentify can update later days without asking every time.- Each user connects their own account. Admin consent allows the app in the tenant. It does not connect users by itself.
- Storage: Synchronization metadata is stored in absentify’s database in Azure North Europe, in line with GDPR. Access is restricted to authorized personnel at absentify GmbH.
Security and data protection
- ISO 27001 certification: absentify is ISO 27001 certified.
- Microsoft 365 App Certification: The app meets Microsoft’s requirements for security, privacy, and compliance.
- Controlled access: Secrets for work location sync are stored in an Azure Key Vault and limited to the people who need them.
Enable work location sync
- Grant permissions: A Microsoft Tenant Administrator selects Activate on Microsoft work location sync under Settings > Microsoft. Microsoft asks for admin consent for the absentify Work Location app.
- When consent succeeds, absentify shows Work location sync is active. If you cancel consent, it shows Microsoft consent was cancelled, so work location sync stays off. If activation fails, it shows Work location sync could not be activated. Please try again.
- Users connect: Each user with a linked Microsoft account opens Your Preferences > Microsoft account (in the app: Settings > Profile > Microsoft account) and turns on Sync my home office days. On the web, signing in can include a short Microsoft step. In Teams they connect from that card. See Your preferences.
What the integration does
- Sets Remote for approved requests whose leave type uses Working Elsewhere - e.g. Home Office and has Counts as leave off.
- Covers only a full working day. Half days are not written.
- Sets the day back when the request is changed, canceled, declined, or deleted, or when the user turns the sync off.
- Does not write vacation or sickness. Those stay on the calendar sync as Away.
- Does not create an absentify request from a work location someone sets in Outlook.
Revoking permissions
- In absentify, go to Settings > Microsoft and turn off Microsoft work location sync. Confirm Are you sure you want to revoke the permission? Remote days that absentify set are reset.
- Sign in to the Microsoft Entra admin center with a Microsoft 365 administrator account.
- Go to Identity > Applications > Enterprise applications.
- Open the absentify Work Location app.
- In Permissions, revoke
Calendars.ReadWriteandoffline_access, or delete the app’s service principal.