Microsoft 365 admins: how do I approve Monty for our tenant?

Someone on your sales team has asked you to let Monty (montyai.co) read and send from the team's inboxes. You approve it once as a Global Administrator on Microsoft's own consent page; Monty then acts only for the mailboxes your team picks. One click, no per-user sign-ins.

  1. 1Open the link you were sent and click Approve on Microsoft. Sign in as a Global Administrator if asked.
  2. 2Microsoft lists the permissions: Read and write mail in all mailboxes, Send mail as any user, and Read all users' full profiles. These are application permissions — the standard shape for a service that acts for a team rather than one signed-in person. Monty's own controls limit it to the mailboxes your team ticks; see the tip below for enforcing that on your side as well.
  3. 3If Microsoft shows a Publisher not verified notice: that is Microsoft's label for a company that has not yet completed its Partner Center verification, which Monty is working through. The permissions and the app are the same either way; the notice is about paperwork, not access.
  4. 4Click Accept. Microsoft sends you back to the Monty page, which confirms it worked and tells you that you can close it. Your colleague now picks which inboxes Monty uses.

To restrict Monty to a specific group of mailboxes at the Exchange level, create a mail-enabled security group containing the sales team and run New-ApplicationAccessPolicy in Exchange Online PowerShell with Monty's app ID, the group, and RestrictAccess. Email hello@montyai.co and we will send the exact command with our app ID filled in. To remove Monty later, open Entra → Enterprise applications → Monty and delete it; every inbox disconnects at once.

Didn’t find what you needed?

Contact support