Skip to content

New: a hosted MCP server. Point Claude at your intake desk. Read more →

Faldaro

Approvals & workflow

Microsoft Forms approval workflows, and what changes for external users

Inside one Microsoft 365 tenant, Forms plus Power Automate is a quick way to route a response for sign-off. The moment the person filling the form, or the person approving it, works somewhere else, the shape of the problem changes. Here is the standard build, and exactly where the edges are.

By the Faldaro team · Published

The standard build: Forms, Power Automate, Approvals

Microsoft Forms collects the response; Power Automate reacts to it; the Approvals connector asks someone to decide. The usual flow, which Microsoft and most tutorials describe in some variation, has five steps:

  1. Trigger: When a new response is submitted. Pick your form in the Microsoft Forms connector. The trigger hands over only a response id.
  2. Get response details. Pass the form id and that response id to fetch the actual answers, which then appear as dynamic content for later steps.
  3. Start and wait for an approval. Choose an approval type, name the approvers, and write a title and details that include the answers the approver needs to see.
  4. Condition on the outcome. Branch on whether the result was approved.
  5. Act on each branch. Send an email, update a SharePoint list or Excel table, post to Teams — whatever “approved” and “rejected” mean for your process.

The approval action offers several types: everyone must approve, first to respond, custom responses (wait for one or wait for all), and sequential approval, where each approver responds in turn. Approvers can answer from an Outlook email, a Teams adaptive card, or the Power Automate action centre.

Two small traps catch almost everyone the first time. Forms owned by a group do not appear in the trigger’s drop-down, so you paste the form id from the address bar by hand. And the first approval flow in a non-default environment provisions a Dataverse database, which needs an environment administrator and takes a few minutes.

External users are two different problems

“External users” usually means one of two people, and they hit different walls:

  • External submitters — a customer, applicant, vendor or policyholder filling in the form.
  • External approvers — a client signing off a change, a landlord approving a request, a partner firm reviewing a referral.

Many real processes have both. Take them one at a time.

When the submitter is outside your organization

Microsoft Forms handles this with its Anyone can respond setting: anyone inside or outside your organization with the link can submit. The trigger fires for these responses the same way it does for internal ones, so the flow above still runs.

What you give up is worth knowing before you promise anything to the team:

  • No verified identity. Recording the respondent’s name is available only when responses are restricted to people in your organization. For an external response, you know who sent it only if you ask — so add a required email question, and treat what is typed there as a claim rather than a verified address.
  • No file uploads. Microsoft’s support documentation states that file upload questions are available only when the form is set to Only people in my organization or Specific people in my organization. For a claim with photos or an application with a CV attached, that is often decisive.
  • No status for the submitter. Once they press Submit, the external person has no view into what happened next. Any update has to be an email your flow sends.

When the approver is outside your organization

This is where most Forms approval projects stall. Power Automate assigns approvals to users in your tenant or environment — and that includes guest users, invited through Microsoft Entra B2B collaboration. Microsoft’s guest-user documentation sets out what that requires:

  • The guest must accept the B2B invitation. Guests who have not accepted are removed from the approval’s assignee list: they receive no email and cannot respond. If every assignee is a pending guest, the approval fails to create.
  • The guest needs a Power Automate licence, assigned either by your tenant or by their home tenant.
  • No approving from the email itself. Actionable approval emails in Outlook are not supported for guest users; a guest follows the link to the Approvals page in your tenant, signs in, and decides there.
  • Tenant settings can block it. Assigning approvals to people outside the environment relies on settings such as AllowAdHocSubscriptions in Entra and on the environment not being restricted to a security group.

For a long-term partner who already works in your tenant, that is manageable. For a client who approves one change request a quarter, it is a lot to ask: an invitation to accept, a sign-in to remember, and a licence question for somebody’s IT department.

Common workarounds, and their costs

Teams in this position tend to reach for one of these:

  • An internal proxy approver. Assign the approval to an internal colleague who emails the outside person, waits for a reply, and clicks Approve on their behalf. It works, but the record says the colleague approved, and the real decision lives in an inbox.
  • Guest accounts for everyone. Workable for a small, stable set of partners; it turns every new approver into an onboarding task.
  • Plain notification emails. The flow emails the outside person and a human updates a list when they reply. Simple, but nothing enforces or records the decision.
  • A form tool built for external approvals. Move the form and its approval step to a tool whose approvers need no account at all. Covered below.

Where the responses live

Two structural points matter for anything you will need to defend later. Forms responses, and any uploaded files, live with the form’s owner — uploads land in the owner’s OneDrive for Business, or the group’s site for a group form. And the approval’s history lives in Dataverse, separate from the response. If the owner leaves, or someone asks “who approved this, and what exactly did they see?”, the answer is spread across several places. Group-owned forms and a flow that writes the outcome back to a SharePoint list alongside the response go a long way here.

When Microsoft Forms is the right answer

If the submitters and approvers are all colleagues, you already pay for Microsoft 365, and the process is short — time-off requests, internal purchase sign-offs, equipment requests — the Forms and Power Automate combination is hard to beat. It is already licensed, it lives where your people work, and approvals from Teams are genuinely pleasant. Do not move a process like that for the sake of it.

The case for another tool gets stronger as more of the people involved sit outside the tenant, as submissions need files or computed figures, and as the process gains steps, deadlines and a need for a record that answers for itself.

Option: an intake platform built for people outside

Faldaro is built around exactly this case — work that arrives from outside the organization and needs a decision. It is one option among several; here is how it handles the two problems above, stated as mechanisms rather than adjectives:

  • Submitters need no account. A form is published on a revocable public link; submitters are never seats. A form that declares a file field accepts uploads from anonymous submitters, and a status link can show them where their submission stands.
  • Approvers need no account either. The workflow’s Request an approval action emails each named approver their own approve/decline link. They see only the fields you chose to show, and decide with a comment. With several approvers, the move fires once everyone has said yes; any no reads as declined.
  • The link can do exactly one thing. An approval link takes the one move you named for approve (and optionally one for decline). If the record has already moved on, the verdict is recorded and nothing moves.
  • Stalls escalate on their own. A waiting state can carry a deadline and the move to take when it passes, and the audit log records that the deadline did it.
  • One record. The response, the decision — who, when, with what comment — and everything that happened afterwards sit on the same submission, in an append-only audit log.

Approvals are on every plan, the free one included. The approvals page shows the feature, the workflow documentation explains every setting, and the Microsoft Forms comparison covers the wider trade-off honestly — including where Microsoft Forms is the better fit.

A quick checklist

  • Are all submitters in your tenant? If not, can you live without verified names and file uploads?
  • Are all approvers in your tenant? If not, will each accept a guest invitation, hold a licence, and sign in to approve?
  • Does anyone outside need to see the status of their submission?
  • When someone asks who approved what, and on what information, where will you look?

If every answer points inside the tenant, build it in Power Automate. If most point outside, choose a tool designed for the outside world.

Questions

Can someone outside my organization approve a Microsoft Forms response?

Only as a guest user of your Microsoft Entra tenant. Power Automate can assign an approval to a guest, but the guest must have accepted the B2B invitation, needs a Power Automate licence from your tenant or their own, and must act from the Approvals page in your tenant — actionable approval emails in Outlook are not supported for guests.

Can external people fill in the form itself?

Yes. Set the form to “Anyone can respond” and anyone with the link can submit. The trade-off is identity: names are recorded only when responses are restricted to your organization, and file upload questions are available only in the organization-only modes.

What happens if an external approver never accepts the guest invitation?

Microsoft’s documentation says guests who have not accepted are removed from the approval’s assignee list: they get no email and cannot respond. If every assignee is a pending guest, creating the approval fails.

Do I need a paid licence to build the approval flow?

The Approvals connector is a standard connector, so any licence that grants Power Automate with standard connectors — including Power Automate rights bundled with many Office 365 and Dynamics 365 plans — is enough to create the flow. Check the licensing guide for your specific plan.

Approvals that work outside your tenant

Anyone submits from a link; approvers decide from their inbox with no account. Free on every plan.

No card required.