Skip to main content

Adding the Spellbook Apps in Microsoft Entra

M
Written by Mustafa Jamal

Overview

Spellbook is deployed centrally through the Microsoft admin centre, so its enterprise application registrations are created automatically in Microsoft Entra ID — there is no manual app registration step required. Two related enterprise applications will appear, both using the same Spellbook diamond icon.

This guide walks through locating both apps, assigning the correct users and groups, and granting admin consent for the permissions each app requests.


Step 1: Locate the Spellbook Apps in Enterprise Applications

1. Sign in to the Microsoft Entra at entra.microsoft.com with a Global Administrator, Application Administrator, or Cloud Application Administrator account.

2. In the left-hand navigation, expand Entra ID and select Enterprise apps, then choose All applications.

3. Both Spellbook apps appear automatically in the list, since they were provisioned when the app was deployed from the admin centre. In this tenant they show up as Spellbook and Spellbook Ass… (name truncated — click into the app to see the full name), both marked with the same diamond icon.

Figure 1. Enterprise applications — All applications, showing both Spellbook apps (diamond icon).


Step 2: Open the App and Review the Overview Page

4. Click directly on the Spellbook application name to open its Overview page.

5. The Getting Started section links straight to the two tasks you need: Assign users and groups, and Permissions (under the Security section in the left-hand menu).

Figure 2. The Spellbook enterprise application Overview page, with Properties and Getting Started.

Note: Repeat every step in this guide for both Spellbook apps — they are separate app registrations, each with its own user assignments and its own admin consent to grant.


Step 3: Assign Users and Groups

Access to most enterprise apps is controlled by explicit assignment. Confirm the right people and groups are assigned before anyone tries to sign in.

6. From the app's left-hand menu, select Users and groups.

7. Review who already has access.

Figure 3. The Users and groups page, listing everyone currently assigned to Spellbook.

8. Select + Add user/group at the top of the page.

9. In the panel that opens, click the Users and groups selector, search for each person or group that needs access, tick the checkbox next to their name, then click Select.

10. Click Assign to save. The new users or groups will now appear in the list shown above.


Step 4: Review Permissions and Grant Admin Consent

Each Spellbook app requests a set of API permissions (in this tenant, three Microsoft Graph delegated permissions: openid, profile, and offline_access). An administrator needs to grant consent on behalf of the organization before they take effect for everyone.

11. From the app's left-hand menu, under Security, select Permissions.

12. Review the permissions table under the Admin consent tab.

13. Click "Grant admin consent for 'Tenant Name'" near the top of the page, then confirm the prompt that follows.

Figure 4. The Permissions page — use the “Grant admin consent for 'Tenant Name'" button highlighted here.

14. Once granted, the column updates to confirm admin consent for each permission.

15. Go back to All applications and repeat Step 4 for the second Spellbook app — its permissions are granted independently and won't be covered by consenting on the first app.


Need additional assistance? Contact our support team at success@spellbook.com

Did this answer your question?