{"id":3718,"date":"2026-05-19T16:49:27","date_gmt":"2026-05-19T21:49:27","guid":{"rendered":"https:\/\/microsoftgeek.com\/?p=3718"},"modified":"2026-05-19T16:49:27","modified_gmt":"2026-05-19T21:49:27","slug":"how-to-set-up-multiple-administrator-approval-for-intune-device-actions","status":"publish","type":"post","link":"https:\/\/microsoftgeek.com\/?p=3718","title":{"rendered":"How to Set up Multiple Administrator Approval for Intune Device Actions"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\">Create the Dedicated Approver Security Group<\/h3>\n\n\n\n<p>This group will house all the administrators authorized to approve MAA requests.<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Sign in to the\u00a0<strong>Microsoft Entra admin center<\/strong>.<\/li>\n\n\n\n<li>Navigate to\u00a0<strong>Entra ID<\/strong>\u00a0>\u00a0<strong>Groups<\/strong>\u00a0>\u00a0<strong>All groups<\/strong>.<\/li>\n\n\n\n<li>Click\u00a0<strong>+ New group<\/strong>.<\/li>\n\n\n\n<li><strong>Group type:<\/strong>\u00a0Select\u00a0<strong>Security<\/strong>.<\/li>\n\n\n\n<li><strong>Group name:<\/strong>\u00a0Give it a clear name (e.g.,\u00a0<code>SG-Intune-MAA-Approvers<\/code>).<\/li>\n\n\n\n<li><strong>Membership type:<\/strong>\u00a0Select\u00a0<strong>Assigned<\/strong>.<\/li>\n\n\n\n<li>Add the administrator accounts that will be authorized to\u00a0<em>approve<\/em>\u00a0the requests to the\u00a0<strong>Members<\/strong>\u00a0list.<\/li>\n\n\n\n<li>Click\u00a0<strong>Create<\/strong>.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Link the Approver Group to an Intune Role<\/h3>\n\n\n\n<p>This step prevents the group from being \u201cinadvertently pruned\u201d from Intune\u2019s data sync, ensuring it remains visible and functional for the MAA policy long-term.<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Sign in to the\u00a0<strong>Microsoft Intune admin center<\/strong>.<\/li>\n\n\n\n<li>Navigate to\u00a0<strong>Tenant administration<\/strong>\u00a0>\u00a0<strong>Roles<\/strong>.<\/li>\n\n\n\n<li>Select an existing, low-impact role, such as the\u00a0<strong>\u201cRead Only Operator\u201d<\/strong>\u00a0role.\u00a0<em>(A custom role with zero permissions is also an excellent option)<\/em>.<\/li>\n\n\n\n<li>Select the\u00a0<strong>Assignments<\/strong>\u00a0tab, and then click\u00a0<strong>+ Assign<\/strong>.<\/li>\n\n\n\n<li>Give the assignment a name.\u00a0Click\u00a0<strong>Next<\/strong>.<\/li>\n\n\n\n<li><strong>Admin Groups:<\/strong>\u00a0Click\u00a0<strong>+ Select groups to include<\/strong>.<\/li>\n\n\n\n<li>Find and select your new\u00a0<strong>Dedicated Approver Security Group<\/strong>\u00a0(e.g.,\u00a0<code>SG-Intune-MAA-Approvers<\/code>). Click\u00a0<strong>Select<\/strong>.<\/li>\n\n\n\n<li>Click\u00a0<strong>Next<\/strong>\u00a0through the remaining settings (<strong>Scope groups<\/strong>\u00a0and\u00a0<strong>Scope tags<\/strong>).<\/li>\n\n\n\n<li>Review and click\u00a0<strong>Create<\/strong>.<\/li>\n<\/ol>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/mrmicrosoft.com\/wp-content\/uploads\/2025\/11\/2025-11-11-17_35_37--300x170.png\" alt=\"How to Set up Multiple Administrator Approval for Intune Device Actions - How-to\" class=\"wp-image-2518\" title=\"How to Set up Multiple Administrator Approval for Intune Device Actions 2\"\/><\/figure>\n<\/div>\n\n\n<h2 class=\"wp-block-heading\">Creating the Multi-Admin Approval Access Policy<\/h2>\n\n\n\n<p>The Access Policy defines&nbsp;<strong>what<\/strong>&nbsp;action is protected and&nbsp;<strong>who<\/strong>&nbsp;is authorized to approve it. This step is performed by the initial administrator (the Requester).<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Sign in to the\u00a0<strong>Microsoft Intune admin center<\/strong>.<\/li>\n\n\n\n<li>Navigate to\u00a0<strong>Tenant administration<\/strong>\u00a0>\u00a0<strong>Multi Admin Approval<\/strong>.<\/li>\n\n\n\n<li>Select the\u00a0<strong>Access policies<\/strong>\u00a0tab and click\u00a0<strong>+ Create<\/strong>.<\/li>\n<\/ol>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/mrmicrosoft.com\/wp-content\/uploads\/2025\/11\/2025-11-11-17_37_01--300x179.png\" alt=\"How to Set up Multiple Administrator Approval for Intune Device Actions - How-to\" class=\"wp-image-2519\" title=\"How to Set up Multiple Administrator Approval for Intune Device Actions 3\"\/><\/figure>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\">Define the Policy Scope<\/h3>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>Name:<\/strong>\u00a0Enter a descriptive name.<\/li>\n\n\n\n<li><strong>Profile type:<\/strong>\u00a0Select\u00a0<strong>Device wipe<\/strong>. Click\u00a0<strong>Next<\/strong>.<\/li>\n\n\n\n<li>Select the\u00a0<strong>Platforms<\/strong>\u00a0to which this policy will apply.<\/li>\n\n\n\n<li>Click\u00a0<strong>Next<\/strong>.<\/li>\n<\/ol>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/mrmicrosoft.com\/wp-content\/uploads\/2025\/11\/2025-11-11-17_39_01--300x105.png\" alt=\"How to Set up Multiple Administrator Approval for Intune Device Actions - How-to\" class=\"wp-image-2520\" title=\"How to Set up Multiple Administrator Approval for Intune Device Actions 4\"\/><\/figure>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\"><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>On the\u00a0<strong>Approvers<\/strong>\u00a0page, click\u00a0<strong>+ Add groups<\/strong>.<\/li>\n\n\n\n<li>Select the\u00a0<strong>Dedicated Approver Security Group<\/strong>\u00a0you created in Step 1.<\/li>\n\n\n\n<li>Click\u00a0<strong>Select<\/strong>, then click\u00a0<strong>Next<\/strong>.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Submit the Policy for Approval<\/h3>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Review the settings on the\u00a0<strong>Review + submit for approval<\/strong>\u00a0page.<\/li>\n\n\n\n<li>Provide a\u00a0<strong>Business justification<\/strong>\u00a0for\u00a0<em>creating the policy itself<\/em>\u00a0(e.g., \u201cImplementing MAA as per security audit requirements to enforce separation of duties.\u201d).<\/li>\n\n\n\n<li>Click\u00a0<strong>Submit for approval<\/strong>.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Activating the Dual Role Policy in Intune<\/h2>\n\n\n\n<p>Since the policy creation is a security-impacting change, it requires approval before it can become active.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Review and Approve the Policy Creation (Approver Role)<\/h3>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>The\u00a0<strong>Approver Admin<\/strong>\u00a0signs in to the\u00a0<strong>Microsoft Intune admin center<\/strong>.<\/li>\n\n\n\n<li>Navigate to\u00a0<strong>Tenant administration<\/strong>\u00a0>\u00a0<strong>Multi Admin Approval<\/strong>\u00a0>\u00a0<strong>All<\/strong>\u00a0<strong>requests<\/strong>.<\/li>\n\n\n\n<li>Locate and select the pending policy creation request.<\/li>\n\n\n\n<li>Add\u00a0<strong>Approver notes<\/strong>.<\/li>\n\n\n\n<li>Click\u00a0<strong>Approve request<\/strong>.<\/li>\n<\/ol>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/mrmicrosoft.com\/wp-content\/uploads\/2025\/11\/2025-11-11-17_48_59--300x187.png\" alt=\"How to Set up Multiple Administrator Approval for Intune Device Actions - How-to\" class=\"wp-image-2522\" title=\"How to Set up Multiple Administrator Approval for Intune Device Actions 5\"\/><\/figure>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\">Complete and Activate the Policy (Requester Role)<\/h3>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>The\u00a0<strong>Requester Admin<\/strong>\u00a0signs back into the Intune admin center.<\/li>\n\n\n\n<li>Navigate to\u00a0<strong>Tenant administration<\/strong>\u00a0>\u00a0<strong>Multi Admin Approval<\/strong>\u00a0>\u00a0<strong>My requests<\/strong>.<\/li>\n\n\n\n<li>The request status will show as\u00a0<strong>Approved<\/strong>. Click the request.<\/li>\n\n\n\n<li>Click\u00a0<strong>Complete<\/strong>.<\/li>\n<\/ol>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/mrmicrosoft.com\/wp-content\/uploads\/2025\/11\/2025-11-11-17_46_50--300x146.png\" alt=\"How to Set up Multiple Administrator Approval for Intune Device Actions - How-to\" class=\"wp-image-2521\" title=\"How to Set up Multiple Administrator Approval for Intune Device Actions 6\"\/><\/figure>\n<\/div>\n\n\n<h2 class=\"wp-block-heading\">Executing a Protected Device Action (The Workflow)<\/h2>\n\n\n\n<p>When an admin attempts a protected action, the workflow immediately triggers:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Initiating the Request (Requester Role)<\/h3>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>The Requester navigates to a device and selects a protected action (e.g.,\u00a0<strong>Device Wipe<\/strong>).<\/li>\n\n\n\n<li>A dialog box appears, showing the MAA requirement.<\/li>\n\n\n\n<li>The Requester enters a mandatory\u00a0<strong>Business justification<\/strong>\u00a0for the device action.<\/li>\n\n\n\n<li>The Requester clicks\u00a0<strong>Submit for approval<\/strong>.<\/li>\n<\/ol>\n\n\n\n<p>The device action is halted. The request is visible in the&nbsp;<strong>My requests<\/strong>&nbsp;tab with the status&nbsp;<strong>Needs approval<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Reviewing and Approving the Action (Approver Role)<\/h3>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>The Approver signs in and navigates to\u00a0<strong>Tenant administration<\/strong>\u00a0>\u00a0<strong>Multi Admin Approval<\/strong>\u00a0>\u00a0<strong>Received requests<\/strong>.<\/li>\n\n\n\n<li>They review the device, the action type, and the Requester\u2019s justification.<\/li>\n\n\n\n<li>They add\u00a0<strong>Approver notes<\/strong>\u00a0(e.g., \u201cVerified user termination date, proceeding with device retire.\u201d).<\/li>\n\n\n\n<li>They click\u00a0<strong>Approve request<\/strong>.<\/li>\n<\/ol>\n\n\n\n<p>The request status changes to&nbsp;<strong>Approved<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Finalizing and Executing the Action (Requester Role)<\/h3>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>The Requester returns to\u00a0<strong>My requests<\/strong>.<\/li>\n\n\n\n<li>The request status is\u00a0<strong>Approved<\/strong>. Click the request.<\/li>\n\n\n\n<li>Click\u00a0<strong>Complete<\/strong>.<\/li>\n<\/ol>\n\n\n\n<p>Intune executes the device action. The complete workflow is recorded in the audit logs.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion:<\/h2>\n\n\n\n<p>By implementing Multiple Administrator Approval, you establish a true governance framework that secures your environment against human error and malicious intent. Every critical device action is now backed by an auditable workflow that confirms who requested it and who provided oversight. This is a non-negotiable step toward modern, compliant security.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Create the Dedicated Approver Security Group This group will house all the administrators authorized to approve MAA requests. Link the Approver Group to an Intune Role This step prevents the group from being \u201cinadvertently pruned\u201d from Intune\u2019s data sync, ensuring it remains visible and functional for the MAA policy long-term. Creating the Multi-Admin Approval Access [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[104],"tags":[],"class_list":["post-3718","post","type-post","status-publish","format-standard","hentry","category-intune"],"_links":{"self":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts\/3718","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3718"}],"version-history":[{"count":1,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts\/3718\/revisions"}],"predecessor-version":[{"id":3719,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts\/3718\/revisions\/3719"}],"wp:attachment":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3718"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3718"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3718"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}