Microsoft Intune
Fundamentals

Use Multi Admin Approval in Intune

In brief

The documentation now clarifies that MAA covers delegated actions and app-authenticated Microsoft Graph API calls when policies are already configured. It also documents per-policy enterprise application exclusions for app-auth calls, including a 50-application limit, second-admin approval, and audit logging.

What Intune admins need to know

Review automation and service-principal access, approver Read permissions, direct group membership, and application exclusions. Delegated calls remain subject to MAA, while excluded app-auth applications can bypass approval for the affected resource type.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Open the full-page diff for complete context.


title: Use Multi Admin Approval in Intune description: Configure Multi Admin Approval to protect your tenant against the use of compromised administrative accounts in Intune. ms.date: 06/15/07/30/2026 ms.topic: how-to ai-usage: ai-assisted ms.reviewer: davidra

When you use any account in the tenant to make a change to a resource that's protected by an access policy, Intune doesn't apply the change until a different account explicitly approves it. Only administrators who are members of an approval group that an access protection policy assigns a protected resource to can approve changes. Approvers can also reject change requests.

MAA enforcement applies to both interactive (delegated) admin actions and application-authenticated (app-auth) API calls made through the Microsoft Graph API. If your organization uses service principals, automation scripts, or third-party applications to manage Intune supportsresources via the Microsoft Graph API, those calls are also intercepted by MAA when the target resource is protected by an access policies for the following resources:policy. For details on how to update your automation to work with MAA, see Use Multi Admin Approval with the Microsoft Graph API. To exclude specific apps from enforcement, see Exclude enterprise applications from an access policy.

  • Apps – Applies to app deployments

    Intune supports access policies for the following resources:

    • Apps – Applies to app deployments, but doesn't apply to app protection policies.
      To approve or reject MAA requests submitted by other admins, an account must meet all of the following requirements:
    1. Approver group membership: The account must be a member of the approver group that's assigned to the access policy for the specific resource type.
    2. Intune role permission: The approver account must have the resource-specific Read permissions permission for the policy type they are're approving. For example, to approve a request for a device delete action, the approver must have ManagedDevices/Read. For a full list of available permissions, see Custom role permissions.
    3. RBAC role assignment for the group: The approver security group itself must be added as a member group to at least one Intune role assignment. If the approver group isn't added to a role assignment, approver group members are removed from the group periodically.

    Role 3: Change requestor

    1. On Approvers, select Add groups and then select a group as the group of approvers for this policy. More complex configurations that exclude groups aren't supported.

    2. On Exclusions, optionally select Add enterprise applications to exclude specific enterprise applications that use app-auth tokens from MAA enforcement for this policy. Excluded applications can modify protected resources without going through the approval workflow. For more information, see Exclude enterprise applications from an access policy.

    3. On Review + submit for approval, review the policy summary including the basics, approvers, and any exclusions. Enter a Business justification, and then select Submit for approval.

    4. Next, use a separate administrative account with Approval for Multi Admin Approval permission to sign in to the admin center to review and approve the new access policy.

    5. Sign back in to the admin center with the first admin account that created the access policy, view the policy, and finalize it by selecting Complete. After Intune applies this policy, configurations for the protected profile type require multiple admin approvals.

    Exclude enterprise applications from an access policy

    When you create or edit an access policy, you can exclude specific enterprise applications from MAA enforcement for that policy. Excluded applications can modify the protected resource type without going through the approval workflow.

    Keep the following details in mind:

    • Per-policy scope — Each exclusion applies only to the access policy where it's configured. An exclusion in one access policy doesn't affect other policies or workloads.
    • Limit — App exclusions are capped at 50 applications per access policy.
    • Approval required — Adding, removing, or modifying exclusions requires approval by a second administrator, just like other access policy changes.
    • Audit logging — All add, remove, and modify actions on the exclusion list are captured in the Intune audit log.

    Submit a request

    To submit a request when Multi Admin Approval is enabled, use your normal process to create or edit a resource.

    Related content

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Email signup will appear here once the Kit form is configured. Until then, use the daily RSS feed.