Approval of an app's permissions for the whole tenant, given by an administrator with the right authority. Application permissions always need it, and owning the app does not grant it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Admin consent in context, with comparison tables and the common traps.
Terms in this definition
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Tenant
A trusted, dedicated Microsoft Entra ID instance that stores the users, groups and app registrations of one organisation. A subscription trusts only a single tenant, although a tenant can be trusted by several subscriptions.
- Application permissions
Microsoft Entra permissions granted to the app itself and used without any signed-in user, which means they reach every user's data. For per-user access they are not least privilege.
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
Related terms
- Admin consent workflow
Feature allowing users to ask an administrator to approve an app they cannot consent to themselves. Nominated reviewers handle the requests, yet the approver must hold a role able to grant admin consent.
- Agent ID Administrator
Privileged role in Microsoft Entra for managing agent identities and blueprints across their lifecycle. Approving partner agent permissions and granting admin consent are beyond it.
- Application Administrator
Microsoft Entra role able to manage every enterprise application and app registration, application proxy included. It may grant admin consent, apart from Microsoft Graph app roles.
- Azure DevOps Administrator
Microsoft Entra role for managing enterprise-level Azure DevOps policies across the organisations connected to the tenant; it gives no rights to register apps or grant admin consent.
- Calendars.ReadWrite
Microsoft Graph permission for creating, reading, updating and deleting events; as an application permission it spans every calendar in the organisation and needs admin consent, while delegated it reaches only the signed-in user's own calendars.
- Daemon app
Service or background process that runs without anyone signed in, authenticating as itself via client credentials, which is why it needs application permissions with admin consent.
- Directory.Read.All
Graph permission for reading users, groups, apps and other directory data. A daemon that reads the directory needs at least this as an application permission, which always requires admin consent.
- Microsoft-registered Azure VPN Client app
App ID that Microsoft has already registered, set as the Audience for point-to-site authentication with Entra ID, so you neither register an app yourself nor grant separate admin consent.