Share via

365 tenant but no 365 admin access and cannot perform entra ID or admin consent actions.

Galley Table 0 Reputation points
2026-04-24T14:34:08.4+00:00

I have a Microsoft 365 tenant (<PII REMOVED>). My account <PII REMOVED> appears as an admin in Azure, but I do not have Microsoft 365 admin center access and cannot perform any Entra ID or admin consent actions.

I cannot grant admin consent for enterprise applications (e.g., Calendly), and I receive “Need admin approval” errors.

Additionally, I cannot access Entra consent settings or submit support requests from the tenant.

I need Microsoft Data Protection / tenant admin recovery assistance to restore Global Administrator functionality and enable admin consent for the tenant.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. AI answer

    2026-04-24T14:35:03.5733333+00:00

    The described behavior matches a scenario where admin consent is required but the current account either lacks effective Global Administrator privileges in Microsoft Entra ID / Microsoft 365, or there is a tenant-level restriction on user consent and risky apps.

    From the tenant side, the only supported way to resolve “Need admin approval” / AADSTS90094 and restore admin consent capability is for a valid privileged administrator or Microsoft support (Data Protection team) to intervene. Forum moderators and tools outside Microsoft support cannot change tenant roles or restore Global Administrator access.

    Actions that must be taken by someone with working admin access or by Microsoft support:

    1. Verify effective admin role and tenant
      1. Sign in to the Azure portal / Microsoft Entra admin center using the suspected admin account.
      2. Confirm the correct tenant (galleytablecom.onmicrosoft.com) is selected.
      3. In Microsoft Entra ID, check Roles and administrators to ensure the account is actually assigned a role such as Global Administrator, Privileged Role Administrator, or Application Administrator.
      4. If the account is not in one of these roles, another Global Administrator must assign the role.
    2. Check consent configuration and risky app blocking Once a working Global Administrator session is available:
      1. Go to Microsoft Entra ID → Enterprise applications → Consent and permissions.
      2. Review User consent for applications:
        • If Do not allow user consent is set, non-admin users will always see “Need admin approval”. Admin consent must be used instead.
      3. If user consent is blocked for risky applications, admin consent is still required even for permissions that normally do not need admin approval. In this case, an audit event with activity Consent to application and status reason like Risky application detected or Microsoft.Online.Security.UserConsentBlockedForRiskyAppsException will appear. Admin consent is required to proceed.
    3. Perform admin consent for affected apps (e.g., Calendly) After Global Administrator access is restored:
      1. Have a Global/Company/Application Administrator access the application.
      2. When the consent screen appears, review the requested permissions and select Consent on behalf of your organization.
      3. If the consent screen does not appear, construct a consent URL with &prompt=consent or use the admin consent URL form:
        • https://login.microsoftonline.com/<Tenant-ID>/adminconsent?client_id=<App-ID>
      4. Ensure all required scopes are configured in the app registration and then grant admin consent.
    4. When tenant-level user consent is disabled If User consent for applications is set to Do not allow user consent, non-admin users will always receive “Need admin approval”. In this case:
      • A Global/Company/Application Administrator must perform tenant-wide admin consent for each required application.
      • If user assignment is required for the enterprise application, users must also be explicitly assigned to the app.
    5. If no working Global Administrator access exists If the only Global Administrator account (or all admin accounts) cannot access Microsoft 365 admin center or Entra admin center, or cannot perform admin consent:
      • Microsoft’s Data Protection team must be engaged to verify identity and restore administrator access.
      • This is done by opening a support request through Microsoft support (for business tenants, typically via the Microsoft 365 Admin Center or by calling the regional support number). The Data Protection team has specific processes to validate ownership and recover admin access when an organization is locked out.
      • Community tools and Q&A cannot perform this recovery; it must go through Microsoft support.

    Once Microsoft support restores Global Administrator functionality, admin consent can be granted as described above and “Need admin approval” errors for enterprise apps like Calendly will be resolved.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.