Подія
9 квіт., 15 - 10 квіт., 12
Кодуйте майбутнє за допомогою ШІ та спілкуйтеся з колегами з Java та експертами на JDConf 2025.
Зареєструватися заразЦей браузер більше не підтримується.
Замініть його на Microsoft Edge, щоб користуватися перевагами найновіших функцій, оновлень безпеки та технічної підтримки.
There might be situations where your end-users need to consent to permissions for applications that they're creating or using with their work accounts. However, nonadmin users aren't allowed to consent to permissions that require admin consent. Also, users can’t consent to applications when user consent is disabled in the user’s tenant.
In such situations where user consent is disabled, an admin can grant users the ability to make requests for gaining access to applications by enabling the admin consent workflow. In this article, you learn about the user and admin experience when the admin consent workflow is on vs when it's off.
When attempting to sign in, users might see a consent prompt like the one in the following screenshot:
If the user doesn’t know who to contact to grant them access, they might be unable to use the application. This situation also requires administrators to create a separate workflow to track requests for applications if they're open to receiving them. As an admin, the following options exist for you to determine how users consent to applications:
When you configure the admin consent workflow, your end users can request for consent directly through the prompt. The users might see a consent prompt like the one in the following screenshot:
When an administrator responds to a request, the user receives an email alert informing them that the request is processed.
When the user submits a consent request, the request shows up in the admin consent request page in the Microsoft Entra admin center. Administrators and designated reviewers sign in to view and act on the new requests. Reviewers only see consent requests that were created after they were designated as reviewers. Requests show up in the following two tabs in the admin consent requests pane:
If configured, all reviewers receive email notifications when:
Requestors receive email notifications when:
The following table outlines the scenarios and audit values available for the admin consent workflow.
Scenario | Audit Service | Audit Category | Audit Activity | Audit Actor | Audit log limitations |
---|---|---|---|---|---|
Admin enabling the consent request workflow | Access Reviews | UserManagement | Create governance policy template | App context | Currently you can’t find the user context |
Admin disabling the consent request workflow | Access Reviews | UserManagement | Delete governance policy template | App context | Currently you can’t find the user context |
Admin updating the consent workflow configurations | Access Reviews | UserManagement | Update governance policy template | App context | Currently you can’t find the user context |
End user creating an admin consent request for an app | Access Reviews | Policy | Create request | App context | Currently you can’t find the user context |
Reviewers approving an admin consent request | Access Reviews | UserManagement | Approve all requests in business flow | App context | Currently you can’t find the user context or the app ID that was granted admin consent. |
Reviewers denying an admin consent request | Access Reviews | UserManagement | Approve all requests in business flow | App context | Currently you can’t find the user context of the actor that denied an admin consent request |
Подія
9 квіт., 15 - 10 квіт., 12
Кодуйте майбутнє за допомогою ШІ та спілкуйтеся з колегами з Java та експертами на JDConf 2025.
Зареєструватися заразНавчання
Модуль
Manage user consent across digital platforms - Training
Manage user consent across digital platforms.
Сертифікація
Microsoft Certified: Identity and Access Administrator Associate - Certifications
Демонстрація функцій ідентифікатора Microsoft Entra для модернізації рішень ідентичностей, впровадження гібридних рішень і впровадження керування ідентичностями.
Документація
Manage consent to applications and evaluate consent requests - Microsoft Entra ID
Learn how to manage consent requests when user consent is restricted, and evaluate a request for tenant-wide admin consent to an app in Microsoft Entra ID.
Configure the admin consent workflow - Microsoft Entra ID
Learn how to configure a way for end users to request access to applications that require admin consent.
Overview of user and admin consent - Microsoft Entra ID
Learn about the fundamental concepts of user and admin consent in Microsoft Entra ID.