The short version
When a teacher clicks "Sign in with Microsoft" on Learning Lens, they are simply using their existing school Microsoft account to log in — the same way they sign in to many other services. We request only the minimum needed to identify them.
On some school and local-authority tenants, Microsoft will show a "Need admin approval" screen. That is your tenant's security policy doing its job — it means users aren't allowed to approve new apps themselves, and an administrator needs to approve Learning Lens once, after which every member of staff signs in normally.
This page tells you exactly what we ask for and how to grant it.
What Learning Lens requests
Learning Lens is a classroom-observation and teaching-quality evidence platform used by school staff. For Microsoft sign-in we request a single delegated permission:
| Permission | Type | Why | Admin consent required |
|---|---|---|---|
User.Read | Delegated | Read the signed-in user's basic profile (name, email) so we can create their account | No |
Plus the standard OpenID Connect sign-in scopes (openid, profile, email).
We do not request access to email, files, calendars, Teams, OneDrive, the directory, or any other organisational data. Sign-in is all we use it for. Staff remain signed in under your tenant's own policies — including your MFA — which means you keep full control of authentication.
Is Learning Lens a verified publisher?
Learning Lens is completing Microsoft's publisher verification (a Microsoft AI Cloud Partner Program / Partner One ID check against our registered domain). Until that badge appears, Microsoft labels new apps "unverified" — this reflects how recently the app was registered, not the safety of the service. Our data is hosted in the EU, governed by UK GDPR, and documented in our privacy policy and data processing agreement.
How to grant consent (one-time, ~2 minutes)
An administrator with the Cloud Application Administrator or Global Administrator role in your Microsoft Entra tenant:
- The simplest route: have a staff member click "Sign in with Microsoft", then on
the "Need admin approval" screen choose "Have an admin account? Sign in with that
account." Sign in as the admin, review the single
User.Readpermission, and tick "Consent on behalf of your organization" before accepting. This approves it for everyone at once. - Or approve it centrally in the Microsoft Entra admin center:
- Identity → Applications → Enterprise applications → Learning Lens → Permissions → "Grant admin consent for [your organisation]".
After either route, staff can sign in immediately with no further prompts.
Optional: restricting who can sign in
Approving the app does not open it to everyone by default. If you want to control which staff can use it, in Enterprise applications → Learning Lens → Properties set "Assignment required?" to Yes, then grant access to specific users or groups under Users and groups. This is entirely your choice and changes nothing on our side.
Questions
If your security or data-protection team would like our DPIA pack, sub-processor list, or penetration/security documentation before approving, contact support@mylearninglens.app and we'll provide it.