You started the Microsoft 365 sign-in, typed the short code at microsoft.com/devicelogin, and the screen you were braced for never arrived. There are no permissions coming up, so you assume the sign-in broke. Or Microsoft said you were signed in, but the card inside Booked Solid sat exactly where it was, so you concluded the card didn't flip and gave up on it. Or you got all the way to a green line and the app is still asking you for something: It is now telling me to turn on Outlook but I don't have that. All three of those show up on the same connection, and none of them means it is broken. This page takes them in order.
A missing permissions screen is usually not a failure
Booked Solid does not register its own Microsoft app for this connection. It signs in through Microsoft's own pre-consented Graph public client, the same one Microsoft's own command line tools use. Because that client is already trusted, a lot of tenants sign you straight through without ever showing a separate "approve these permissions" list. This is especially common if you, or your IT admin, ever consented to Microsoft Graph access before.
So treat no permissions screen as normal rather than as an error. Hunting for a consent list your tenant may never show you is a dead end, and its absence tells you nothing either way about whether the sign-in landed. Only the card inside the app tells you that, so go and look at the card instead.
Check the card, not the consent screen
The only thing that tells you whether the sign-in landed is the Microsoft 365 (Outlook, Teams) card inside the app. Nothing gets pasted back from Microsoft. The app keeps asking Microsoft every few seconds in the background and flips the card by itself the moment Microsoft finishes.
- Open More > Connections.
- Scroll past Mail & calendars down to the Tool access (optional) section. Some help center articles still call this section Optional add-ons.
- Find the Microsoft 365 (Outlook, Teams) card and look at what it says right now.
A finished sign-in shows a green line reading Signed in as you@example.com with can save Outlook drafts after it (or read only, if this sign-in was never granted the draft permission).
The two questions support will ask you
These are the exact two questions, and answering them yourself gets you to the right fix faster than a ticket will.
- What does the Microsoft 365 card show right now: still the device code, a green Signed in as ... line, or a red line of text?
- At microsoft.com/devicelogin, after you typed the code and signed in, did it land on the page that says "You have signed in...", or did it say something about needing approval or an admin?
| What the card shows | What it means |
|---|---|
| Still the device code | Microsoft has not confirmed yet. If you already finished at microsoft.com/devicelogin and the code is still sitting there a minute later, run the whole sign-in again. |
| Green Signed in as ... | The sign-in worked. You still have one button left to press. See the Turn on section below. |
| A red line of text | Read the wording. It usually says the code expired, the sign-in was declined, or the sign-in did not finish. Start the sign-in again for a fresh code. |
If the card did not flip, run the whole sign-in again from scratch
This is the fix, and it is far less clever than it sounds. Do not assume the connection is broken after one attempt that went nowhere. The customer this article came from wrote It didn't flip so I tried it all again, and on that second run the permissions come up as well as the card flipping and saying that I was signed in. Same account, same computer, same steps. The second pass simply completed.
- On the Microsoft 365 (Outlook, Teams) card, click Sign in to Microsoft to get a brand new code. Do not reuse the old one.
- Open microsoft.com/devicelogin in your own browser, on any device, and type the new code.
- Sign in with your Microsoft account as you normally would. If a permissions list appears this time, approve it. If none appears, that is fine too.
- Leave Booked Solid open and watch the card. It flips on its own.
Two things worth knowing while you do this. The device code lasts about 15 minutes and then dies, so if you walked away mid-way, that alone explains a card that never moved. And starting a second Microsoft sign-in somewhere else in the app invalidates the first code, so run one sign-in at a time.
If the card turns red and Microsoft's page mentioned approval or an admin, that is a different problem and repeating the sign-in will not clear it. Some organizations switch off user consent for Microsoft Graph, which means you are not allowed to approve the access yourself and a tenant admin has to do it. Open a ticket with the exact red wording and we will give you the admin consent path.
Signed in is not connected: the Turn on button everyone misses
This is the step that ended the ticket this article came from. The green Signed in as ... line is not the finish line. On that same Microsoft 365 (Outlook, Teams) card, right next to the green line, there is a separate Turn on button (with Sign out beside it). Pressing Turn on is what makes the connection live for Otto. Until you press it, the app keeps prompting you and nothing reads your mailbox, no matter how successfully you signed in.
That is the whole gap between signed in but not connected. One customer summed up the ending in four words: It went on after I clicked it. If the card is green and the app is still nagging, this button is the answer.
"Turn on Outlook but I don't have that"
This one deserves its own section because the wording genuinely misleads people. The word Outlook in the card's status note (can save Outlook drafts) does not mean the Outlook desktop program is required, and it does not mean you have to install anything. It means that any draft Otto prepares lands in that mailbox's own Drafts folder up in Microsoft's cloud. You can then open and send it from Outlook on the web, from your phone, or from whatever mail app is signed into that account.
If you do not have the Outlook program on your computer, press Turn on anyway. Nothing is missing.
Do not confuse this with the separate Outlook on this computer card further down the same list (it appears as Outlook app on this computer when you are adding an email account). That card exists only for people who run the Outlook desktop program locally, and it is described in Connect Outlook and desktop mail (Microsoft 365). If your mail lives in the Microsoft 365 cloud, ignore that card completely. The Microsoft 365 card already reads that mailbox directly from Microsoft, whether or not any mail program on your computer is open.
The loop to avoid: app passwords and "Mail app on this computer"
Be warned about this one, because it has cost a customer five hours. Once Microsoft 365 is connected, do not go back to Mail & calendars and try to add the same mailbox a second time as an email account. If you pick Mail app on this computer there, you end up at Found a mail app for you@example.com, but Booked Solid cannot read it yet. Choose IMAP and use a provider-issued app password for background inbox listening. That drops you right back at the app password you were trying to avoid, which on Microsoft 365 means loosening your account security. The device code sign-in exists precisely so you never have to do that.
The plain limits, so nobody loops again:
- Booked Solid cannot read the Apple Mail app on your Mac directly. There is no setting for it and no workaround. If your mail is a Microsoft 365 account that Apple Mail happens to display, the Microsoft 365 card is your route, and Apple Mail keeps working alongside it untouched.
- The Microsoft 365 card holds one Microsoft account at a time. Signing a second account in replaces the first rather than adding to it. If you need two mailboxes connected side by side, open a ticket and say which two and what each is for, so it can be logged as a feature request.
What this connection can and cannot do
- Your Microsoft password never touches Booked Solid. The whole sign-in happens on Microsoft's own site, and what gets stored on your computer is a token in your operating system keychain.
- Read access covers your profile, mail, calendar, Teams chats, and files.
- The only write permission requested is draft creation (Mail.ReadWrite). The permission to send mail (Mail.Send) is deliberately never requested, so Otto structurally cannot send from your Outlook. Sending stays with you.
- For Microsoft 365 the Drafts need your OK toggle is forced on and cannot be switched off, so outgoing Microsoft 365 drafts always wait for your approval. See Settings > Permissions: how far each connected tool can reach.
- If your card says
read onlyand you enabled draft creation afterwards, that older sign-in does not carry the draft permission. Sign out on the card and sign back in. This is covered in Microsoft 365 by device code: what Otto can and cannot do in Outlook. - If the connection refuses to switch on with Sign in to Microsoft first (on its card), then switch it on, finish the sign-in first. That note and the other two switch-on blockers are covered in An add-on refuses to turn on: the three blockers (key, sign-in, Node.js).
If it still does not work
Email bookedsolid@kivimedia.freshdesk.com and a person will help. To skip a round trip, include these three things: what the Microsoft 365 card says word for word right now, what the microsoft.com/devicelogin page said after you entered the code, and whether the account is a personal Microsoft account or a work or school one. Those three answers are usually enough to name the fix in the first reply.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article