Approving an Application Consent in Azure AD

diegotconti 1 Reputation point
2022-05-19T18:38:24.79+00:00

Hello,
I'm a little confused with the Approve action for Azure AD app consent. The approval action is defined as "Granting admin consent to the application will add it to your tenant and all users will be able to access it unless you restrict access to the application." However, I have noticed after approving a specific app that if another user requests the same application, a new consent request will be generated. Is this normal behavior?
Thanks,
Diego C

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,664 questions
0 comments No comments
{count} votes

5 answers

Sort by: Most helpful
  1. Andy David - MVP 142.3K Reputation points MVP
    2022-05-19T20:47:31.133+00:00

    Can you confirm that app has all the perms admin granted for it?
    My thought is that either its not been granted or a new permission was requested by the next request.

    0 comments No comments

  2. diegotconti 1 Reputation point
    2022-05-19T22:29:32.133+00:00

    Hello Andy and thanks for the reply. I don't know if I understood it correctly but here is an example for one application:

    1. In the Enterprise Application blade, the app has been consented with the following permissions:
      203779-permissions-consented.png
    2. The same app is pending admin consent for the following permissions which have already been granted:
      203839-new-app.png

    Thanks,
    DC

    0 comments No comments

  3. 2022-05-20T07:45:12.57+00:00

    Hello @diegotconti , there are many types of consents experiences, some can replace others, some cannot. The first type that you mention allows a multi-tenant app (an app from another tenant) to be used. This an admin consent. The second type is a consent given by each user for his own personal/delegated permissions. This is a user consent. Both may be required depending on various factors like app permissions, policies, etc. That being said you can save the users from consenting their own personal/delegated permissions granting tenant-wide admin consent to an application.

    For more information, please take a look to:

    Let us know if this answer was helpful to you or if you need additional assistance. If it was helpful, please remember to accept it so that others in the community with similar questions can more easily find a solution.


  4. Andy David - MVP 142.3K Reputation points MVP
    2022-05-20T13:12:52.007+00:00

    Can you click on the admin consent menu and see if that has been allowed?

    204125-image.png


  5. Andy David - MVP 142.3K Reputation points MVP
    2022-05-20T22:14:00.427+00:00
    0 comments No comments