Skip to Content
Admin & Team SettingsMicrosoft (Entra)

Setting Up Town for Your Organization

This guide walks a Microsoft Entra administrator through enabling Town for the users in your tenant. There are two required steps and a couple of optional settings.

Setup should take about five minutes.

Before you start

You need one of the following Microsoft Entra roles to grant consent on behalf of your organization. Any one of these is sufficient for Town:

  • Cloud Application Administrator
  • Application Administrator
  • Privileged Role Administrator
  • Global Administrator

You’ll use the Microsoft Entra admin center .

When you grant tenant-wide admin consent, you give Town access to the permissions it requests on behalf of everyone in your organization, so individual users aren’t prompted to consent when they sign in.

  1. Sign in to the Microsoft Entra admin center .
  2. Browse to Entra ID > Enterprise apps > All applications.
  3. In the search box, enter Town and select it from the results.
    • If Town doesn’t appear: it is added to your tenant the first time a user attempts to sign in. Have one user start the Town sign-in once, then return here. (You can also use the direct consent link below instead.)
  4. Under Security, select Permissions.
  5. Select Grant admin consent for <your organization>.
  6. Sign in if prompted, review the permissions in the Permissions requested dialog, and select Accept.

After consent is granted, the permissions appear in the list with Granted by: An administrator.

If Town hasn’t appeared in your tenant yet, or you prefer not to search for it, you can grant consent using this URL. Replace {tenant} with your tenant ID or any verified domain name (for example, contoso.com):

https://login.microsoftonline.com/{tenant}/adminconsent?client_id=2a2566c0-c7df-4eac-a0bb-c5b9052ea825

Open the link, sign in with an account that can grant consent, review the permissions, and accept.

Step 2 — Confirm that user assignment is not required

By default, once admin consent is granted, all users in your tenant can sign in to Town. This is controlled by the Assignment required? setting, which defaults to No.

Confirm the default is in place:

  1. In the Microsoft Entra admin center, browse to Entra ID > Enterprise apps > All applications and select Town.
  2. Under Manage, select Properties.
  3. Check that Assignment required? is set to No.

If it’s already No, you’re done — all your users can now sign in to Town. No per-user allowlisting is needed.

Optional — Restrict Town to specific users or groups

If you’d rather limit Town to a subset of your organization, you can require assignment. Admin consent still covers the permission grant; assignment controls who can actually use the app.

  1. On the Town enterprise application, go to Properties and set Assignment required? to Yes.
  2. Go to Users and groups > Add user/group.
  3. Assign the users — or, recommended, a security group — that should have access.

Only assigned users (or members of assigned groups) will be able to sign in. We recommend assigning a group rather than individuals so you can manage access by group membership over time.

Optional — Show Town in the My Apps portal

If you want users to launch Town from their Microsoft My Apps portal :

  1. On the Town enterprise application, go to Properties and set Visible to users? to Yes.
  2. Under Users and groups, assign the users or groups who should see the Town tile.

Both steps are required. Town appears in My Apps only for users (or members of groups) explicitly assigned to the app — even when Assignment required? is No. Setting Visible to users? on its own won’t surface the tile. If your users always start from Town’s own URL, you can skip this section.

Verifying the setup

Have a standard (non-administrator) user sign in to Town. With admin consent granted and assignment not required, they should reach Town without seeing a consent or approval screen.

Troubleshooting

A user sees “Approval required” when signing in. Admin consent hasn’t been granted in your tenant yet, or was granted in a different tenant. Repeat Step 1.

A specific user can’t sign in, but others can. Assignment required? is likely set to Yes and that user isn’t assigned. Either add them under Users and groups, or set Assignment required? to No (see Step 2).

Town isn’t listed under Enterprise applications. The app is provisioned on first sign-in attempt. Have a user start the Town sign-in once, or use the direct consent link in Step 1.

Quick reference

TaskWhereSetting
Grant access for all usersEnterprise apps > Town > PermissionsGrant admin consent
Allow all tenant users (default)Enterprise apps > Town > PropertiesAssignment required? = No
Restrict to specific users/groupsEnterprise apps > Town > Properties, then Users and groupsAssignment required? = Yes + assign
Show in My Apps portalEnterprise apps > Town > Properties, then Users and groupsVisible to users? = Yes + assign users/groups
Last updated on