The distinction
When an app connects to a work or school Microsoft account, it may request permission to use data such as a calendar or contacts. The user can approve some requests; an organization administrator may approve others for the tenant. Both can make an app appear in the user's portal, but the user controls only consent personally granted.
Why it matters
Imagine a note-taking app you tested last month. You can inspect its user-granted access in My Apps and revoke that consent if the integration is no longer useful. A separate company-wide scheduling integration may have admin-granted permissions. There will be no user-side Revoke control for that approval, so IT needs to assess it.
What revocation does not do
Removing access may interrupt an app, and it does not erase information previously copied. Microsoft's
My Apps guidance shows both sections and states the administrator-consent limit. If an unfamiliar app appears, report its name and displayed permissions to your organization's security team rather than assuming either type of consent is harmless.