Loading

Error Accessing App After Uninstall: How to Assign the "Approve Uninstalled Connected Apps" Permission

Julkaisupäivä: Jul 1, 2026
Kuvaus

After a connected app is uninstalled from a Salesforce org, users who attempt to access that app receive an error indicating their request has been denied. This article explains the "Approve Uninstalled Connected Apps" system permission and when to assign it versus when the correct fix is to reinstall the app.

You are affected if a user receives an OAuth access denial error or cannot use an integration after the associated connected app was uninstalled, removed, or is in an uninstalled state.

Cause
Connected App Is Not Installed in the Org

Salesforce automatically denies attempts to use connected apps that are not installed in the org. This is a security control to prevent unauthorized access via uninstalled apps. Users without the "Approve Uninstalled Connected Apps" permission have no way to proceed without either reinstalling the app or being granted this permission.

User Lacks the Required System Permission

The "Approve Uninstalled Connected Apps" system permission allows a user to access connected apps that are not installed in the org. By default, only administrators with this permission (or system admins with Modify All Data) can access uninstalled apps.

Ratkaisu
Option A: Install the Connected App (Preferred)

If the connected app is used by multiple users or was removed unintentionally, reinstalling the app is the most appropriate fix:

  1. Find the app on AppExchange or through the installation URL provided by the app publisher.
  2. Install it with the appropriate access level (Admins Only, All Users, or Specific Profiles).
  3. Verify that users can access the app after installation.
Option B: Assign the "Approve Uninstalled Connected Apps" Permission

For trusted admin users who need to access apps that are not installed — for example, during troubleshooting or in specific integration scenarios — assign the permission via a Permission Set:

  1. From Setup, in the Quick Find box, enter Permission Sets, and select Permission Sets.
  2. Open an existing permission set or click New to create one.
  3. Click System Permissions.
  4. Click Edit.
  5. Enable Approve Uninstalled Connected Apps.
  6. Click Save.
  7. Assign the permission set to the affected user.
Warning: The "Approve Uninstalled Connected Apps" permission is intended only for highly trusted users such as system administrators. Granting this permission to non-admin end users allows them to access any uninstalled connected app, which is a security risk. Use Option A (reinstall the app) for regular end users.
Option C: Unblock via Connected Apps OAuth Usage

If the app is blocked at the org level rather than uninstalled:

  1. From Setup, in the Quick Find box, enter Connected Apps OAuth Usage.
  2. Find the app in the list.
  3. If it shows as blocked, click Unblock.
FAQ
Q: A user is getting an OAuth error after we uninstalled a connected app. Which option should I use?
If the app should be in use by your users, reinstall it (Option A). The "Approve Uninstalled Connected Apps" permission is for admins, not end users. Assigning it to end users creates a security gap.
Q: Does this permission require a specific license?
Yes. The "Approve Uninstalled Connected Apps" permission is available only to users with a full Salesforce license. It is not available for Platform license users or Experience Cloud users.
Q: I assigned the permission but the user still can't access the app. What should I check?
Verify that the OAuth policies on the connected app itself allow the user's access level. Also check Setup → Connected Apps OAuth Usage to confirm the app is not explicitly blocked at the org level.
Knowledge-artikkelin numero

005388257

 
Ladataan
Salesforce Help | Article