Azure AAD应用普通用户登录需管理员审批问题求助
Hey there, let's troubleshoot why your regular users are stuck with that "Admin approval required" prompt while admins can log in smoothly. This is a super common issue, so let's walk through the key configuration checks step by step:
1. Check API Permissions & Admin Consent
First, head over to your App Registration (not the Enterprise App) and navigate to the API Permissions tab:
- Look at the permissions you've added. If any permission has the label "Requires admin consent" (like Microsoft Graph's
User.Read.AllorMail.Send), regular users can't grant this permission on their own. - Fix:
- If you don't actually need that elevated permission, swap it for a user-consentable one (e.g.,
User.Readinstead ofUser.Read.All). - If the permission is necessary, click the Grant admin consent for [Your Tenant Name] button at the top of the page. This approves the permission for all users in your tenant, so they won't see the prompt anymore.
- If you don't actually need that elevated permission, swap it for a user-consentable one (e.g.,
2. Verify Enterprise App User Assignment Settings
Go to your Enterprise Application and check two key areas:
- User and Groups tab: If you've assigned specific users/groups here, make sure your regular users are included in that list.
- Properties tab: Look for the "User assignment required?" toggle. If this is set to Yes but you haven't added regular users to the assignment list, they'll hit the approval block.
- Fix: Either toggle "User assignment required?" to No (allowing all users to access the app), or add your regular user groups/individuals to the User and Groups list.
3. Review Azure AD's User Consent Policy
Navigate to Azure Active Directory → Enterprise Applications → User Settings:
- Find the section "User consent to applications". If this is set to "Users cannot consent to any application" or "Users can consent to apps from verified publishers, for selected permissions only" (and your app's permissions don't fall into the allowed category), regular users can't self-approve access.
- Fix: Adjust the policy based on your security needs. For example, you can allow users to consent to low-impact permissions (if your app's permissions qualify) or enable full user consent (note: this has security tradeoffs, so evaluate carefully).
4. Check for Conditional Access Policies
Occasionally, a conditional access policy might be enforcing admin approval for regular users:
- Go to Azure Active Directory → Conditional Access and look for policies targeting your app or regular user groups. Check if any policy includes a control like "Require admin approval".
- Fix: Modify or disable the policy if it's unnecessarily restricting regular user access.
Start with the first two checks—they're the most likely culprits. Once you adjust those settings, your regular users should be able to log in without the admin approval prompt just like admins do.
内容的提问来源于stack exchange,提问作者blackbird

