Article
Microsoft 365 Support Access and Admin Consent Governance Guide
itperfection.com
Quoted on this wiki
Every place a page here uses this source, in the order the words come in it.
Interactive/non-interactive sign-ins “Assignment and owner changes” Unusual resource access and failed activity
Identify the principal, permission model, and revocation object “Is user presence required? Is the scope necessary? Can user consent be limited to low-risk permissions and verified publishers?” Request, approver, decision, service request, duration, email/history, audit records; deny or allow the approved period to expire.
Do not collapse five different access paths into “vendor access” “An OAuth consent grant, an enterprise application assignment, a partner’s GDAP relationship, an administrator role, and a Microsoft Customer Lockbox request are not interchangeable.” User and admin consent
Do not collapse five different access paths into “vendor access” “They use different identities, approval mechanisms, scopes, time limits, logs, and revocation methods.” User and admin consent
Do not collapse five different access paths into “vendor access” “Each needs a named owner and a reproducible decision record.” User and admin consent
User and admin consent “Controls whether an application can receive delegated or application permissions and who is authorized to approve the requested scope.” Enterprise applications
Approve safely “Use the correct privileged role, record the approver, grant only the reviewed scope, and avoid unrelated changes.” Monitor
Partner security groups assigned to roles “Named partner users and role purpose” MFA/Conditional Access considerations
MFA/Conditional Access considerations “Joiner/mover/leaver process” Emergency elevation procedure