Read&Write for iOS and Android: needs admin approval when signing in with Microsoft
Note: This article applies to organizations using Azure Active Directory (Microsoft Entra ID) for authentication on mobile devices.
Some organizations restrict the ability for users to consent to third-party applications accessing their profile data. When this is the case, students or staff attempting to sign into the Read&Write for iPad or Read&Write for Android app will see a message stating:
"Need admin approval" "Read&Write needs permission to access resources in your organization that only an admin can grant. Please ask an admin to grant permission to this app before you can use it."
Given this configuration, a Global Administrator must take action to allow users to access the mobile application.
Solution 1: A Global Administrator grants consent
The most efficient way to resolve this for all users is for an administrator to perform a one-time "Admin Consent."
-
Sign in as an Admin: An IT Administrator should open the Read&Write app on a mobile device and attempt to sign in using their Global Admin credentials.
-
Grant Consent: When the "Permissions requested" window appears, the admin must check the box: "Consent on behalf of your organization."
-
Accept: Click Accept.
Once this is done, the application is "approved" for the entire tenant, and non-admin users will no longer see the approval block.
Solution 2: Manual Approval via Azure Portal
If an admin cannot sign in via a mobile device, they can grant permission directly through the Azure/Entra administration dashboard:
-
Navigate to the Azure/Entra Admin Center > Identity > Applications > Enterprise applications.
-
Search for "Read And Write" or “ReadWrite Android”
-
Select Permissions from the left-hand menu under the Security section.
-
Click the blue button labeled "Grant admin consent for [Your Organization Name]".
-
Follow the prompts to sign in and confirm the permissions.
Read&Write iOS

Read&Write Android

Solution 3: Assigning Specific Users (Optional)
If your organization does not want to grant access to everyone, you can restrict the app to specific groups:
-
In the Enterprise Applications menu for Read&Write, go to Properties.
-
Ensure "Assignment required?" is set to Yes.
-
Go to Users and groups and add the specific student or staff groups that require access to the mobile apps.
Common Troubleshooting for Mobile
-
Sign-in Loop: If users are stuck in a loop after approval, ensure the device has a stable internet connection and try clearing the "Site Data" or "Cache" within the app settings.
-
MDM Deployment: If you are using an MDM (like Jamf or Intune) to push the app, ensure that you haven't also restricted "User Sign-in" via a separate mobile configuration profile.
Still need help? Contact your IT Support Desk or reach out to Texthelp Support.