"Need admin approval" still showing after admin conset granted in portal

Casey 21 Reputation points
2022-10-21T19:16:27.603+00:00

An Azure AD admin in my organization exposed an API for our application and added a scope with admin-only consent enabled. We then added the scope to the configured permissions and the admin granted consent for the application. I see the green checkmark in the "Status" column for the scope.

253138-screen-shot-2022-10-21-at-105942-am.png

However, when trying to login with that custom scope request, I am still seeing the "Need admin approval" screen. I was expecting this not to be necessary since it was granted in the portal.

Are there additional steps that need to be taken to grant the approval for all users?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Cristian SPIRIDON 4,486 Reputation points Volunteer Moderator
    2022-10-23T12:44:07.573+00:00

    Hi,

    To add admin consent for an api you have to go enterprise app and select your respective app/api and give consent:

    https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/grant-admin-consent#grant-tenant-wide-admin-consent-in-enterprise-apps

    That is the place where the associated service principal is managed.

    Hope this helps!

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.