2.1 Ensure the admin consent workflow is enabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The admin consent workflow gives admins a secure way to grant access to applications that require admin approval. When a user tries to access an application but is unable to provide consent, they can send a request for admin approval. The request is sent via email to admins who have been designated as reviewers. A reviewer takes action on the request, and the user is notified of the action.

Rationale:

The admin consent workflow (Preview) gives admins a secure way to grant access to applications that require admin approval. When a user tries to access an application but is unable to provide consent, they can send a request for admin approval. The request is sent via email to admins who have been designated as reviewers. A reviewer acts on the request, and the user is notified of the action.

Impact:

To approve requests, a reviewer must be a global administrator, cloud application administrator, or application administrator. The reviewer must already have one of these admin roles assigned; simply designating them as a reviewer doesn't elevate their privileges.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To enable the admin consent workflow, use the Microsoft 365 Admin Center:

Navigate to Microsoft Entra admin center https://entra.microsoft.com/.

Click to expand Azure Active Directory > Applications select Enterprise applications.

Under Security select Consent and permissions.

Under Manage select Admin consent settings.

Set Users can request admin consent to apps they are unable to consent to Yes under Admin consent requests.

Under the Reviewers choose the Roles and Groups that will review user generated app consent requests.

Set Selected users will receive email notifications for requests to Yes

Select Save at the top of the window.

Default Value:

Users can request admin consent to apps they are unable to consent to: No

Selected users to review admin consent requests: None

Selected users will receive email notifications for requests: Yes

Selected users will receive request expiration reminders: Yes

Consent request expires after (days): 30