Outbound Wiki

Article

Microsoft Entra ID: Admin Consent Workflow for Secure Application ...

cloudcoffee.ch

Open at publisher

Quoted on this wiki

Every place a page here uses this source, in the order the words come in it.

  1. The reviewer now has the option to either deny (2) or block (1) it. Denying means that the current approval request is rejected once. Blocking, on the other hand, prevents any future approval requests for this application from being submitted. The reviewer can view, deny, or block an approval request. If the requested permissions are appropriate, the request can be approved by clicking Accept.

    In AI SDR agent human approval

  2. The reviewer can view, deny, or block an approval request. To view the requested permissions and approve them, one of the following roles is required: Global Administrator, Privileged Role Administrator or Cloud Application Administrator. If the requested permissions are appropriate, the request can be approved by clicking Accept. In the Microsoft Entra admin center(https://entra.microsoft.com) navigate toEntra ID > Enterprise apps > All applications >Select application> Permissions, to view the granted permissions. The application is now authorized and ready for use within the organization.

    In AI SDR agent human approval

  3. Enable Admin Consent Workflow Set this option to Yes to activate the Admin Consent Workflow, allowing users to submit access requests to designated reviewers. Assign reviewers Specify users, groups, or roles responsible for reviewing and approving access requests. Enable email notifications Notify reviewers via email when new access requests are submitted.

    In Outbound stack governance

  4. Roles For configuring the Admin Consent Workflow, reviewing requests, and approving or denying access requests, the following roles are appropriate based on the principle of least privilege: * Details about these roles can be found here: Grant tenant-wide admin consent to an application – Microsoft Entra ID | Microsoft Learn

    In Outbound stack governance