Private Tenant Customer Setup Guide of DataMapper: Global Admin
DataMapper is a compliance and data-mapping product by Safe Online ApS.
What is this guide for?
This guide is for creating DataMapper in your own environment on Private Tenant. It requires a Global Administrator to explicitly approve the application before it can be used.
This is a one-time action. It takes less than 5–10 minutes and does not change any security settings in your tenant, it only grants DataMapper the specific permissions listed in Step 3 of this guide.
Who must do this: A Global Administrator (or an account that has been delegated Privileged Role Administrator) in your Azure / Microsoft 365 Tenant.
Time required: Approximately 5-10 minutes. Safe Online will have sent you the consent link beforehand.
Step 1: Receive the consent link from Safe Online
Safe Online will send you a link by email. It looks like the URL below. This link is unique to your organisation — it contains your tenant-id and the DataMapper client-id.
https://login.microsoftonline.com/{your-tenant-id}/adminconsent?client_id=b5566749-786c-4138-b171-0680f46d5c38&redirect_uri=https://www.bysafeonline.com
App name: DataMapper-Multi-Tenant-App - ClientID: b5566749-786c-4138-b171-0680f46d5c38
Do not forward this link to a non-admin colleague - Microsoft will show them a 'need admin approval' message and the consent will not be granted
Step 2: Open the link while signed in as Global Admin
Open a browser and make sure you are signed in with your Global Admin account. Then paste the consent link in the address bar and press Enter.
If you are signed in with a different account, you can use a private/incognito window or choose "Sign in with a different account" on the Microsoft login screen.
Important: If you see 'need admin approval' screen (shown below here) instead of the permission screen, it mens you are not signed in as a Global Admin. Sign out and sign back in with the correct account credentials.
Important: If you see a "Need admin approval" screen (shown below) instead of the permissions screen, it means you are not signed in as a Global Admin. Sign out and sign back in with the correct account.
What a non-admin sees — this means the wrong account is signed in
correct account.
What a non-admin sees — this means the wrong account is signed in

Step 3: Review the permissions and click 'accept'
Microsoft will display a consent screen listing the permissions DataMapper is requesting. Review the list, then click Accept to grant consent on behalf of your organisation.
DataMapper requests the following Microsoft Graph permissions:
| Permission Scope | Type | What it allows DataMapper to do |
| Application.ReadWrite.OwnedBy | Application | Manage apps that this app creates or owns |
| User.Read | Delegated | Sign in and read the profile of the signed-in user |
Note: Several permissions include write access (ReadWrite.All). These are used during the initial EDGE deployment and provisioning phase. Discuss with Safe Online if any permissions can be scoped down after initial setup is complete.
Microsoft admin consent screen — Datamapper-Multi-Tenant-App, Safe Online ApS

Step 4: Verify DataMapper appears in Enterprise Applications
After accepting, you will be redirected to the Safe Online website. DataMapper is now registered in your tenant. You can verify this in the Azure portal.
To confirm the app was registered:
- Go to portal.azure.com
- Search for Enterprise applications
- Search for "Datamapper-Multi-Tenant-App-V2" or by ClientID: b5566749-786c-4138-b171-0680f46d5c38
- The app should appear with status Enabled
Part 1 complete. Notify Safe Online team that admin consent has been granted. They will confirm receipt and send instruction for next steps.