Microsoft Intune Multi Admin Approval

by George Herkes

For those who have been concerned about rogue administrators making changes, or have requested a second pair of eyes validate live changes, you may be interested in a recently expanded feature within Intune: Multi admin approval. This is actually a feature that’s been available for some time – however it’s initial limited scope for it’s launch may have seen it dismissed and since forgotten. Yet Microsoft have just announced that this feature now includes Device and Compliance policies, which means it covers the vast majority of Intune items and may plug an important gap for customers and MSP’s alike.

“Multi‑Admin Approval in Intune ensures no single individual can make high‑risk endpoint configuration changes without peer validation, reducing security, operational, and compliance risk.”

With Multi Admin approval, configuration within Intune can be set to protected – this covers a range of tasks, including edit, creation and deletion of nearly* everything within Intune. This includes: 

  • Applications – useful to further protect assignment of expensive or licensed applications and control supersedence 
  • Configuration and Compliance Policies – help ensure that malicious actors cant relax or amend your crucial security and control via Intune
  • Device actions, such as wiping or removing devices
  • Scripts, including both platform-specific (inc. PowerShell) and remediation scripts

Having the above protected is a great step towards greater governance of your environment – it will help reduce the likelihood of misconfiguration, insider risk, and service disruption, while strengthening auditability and regulatory compliance. 

Setting up multi admin approval is straightforward – but should be considered as part of your overall approval processes. You’ll need to make sure that at least TWO administrators exist with suitable access within Intune and pay close attention to the fact that currently these notifications do not go outside of the admin console – there are no email notifications by default, although we already see opportunity to tailor this to an environment through other means.

Setting up Multi Admin Approval for Windows based Applications

As the administrator who wants to make a change – nothing really changes beyond the final step of a monitored change  – before your change is commited, you’ll be asked to enter justification that’ll be seen by your approval administrator.

As an approval administrator, you’ll need to head to the new Multi Admin Administration portal and review received requests on a regular basis – it’s important to note that changes have 30 days before they automatically expire, at which point they’ll need to be re-created in full.

A new dedicated Multi Admin Approval page is available under Intune’s Tenant Admin menu

Now, a separate Administrator will need to approve our change by heading to the same menu, here they can provide further justification as to why the change has been approved or denied:

Our request then moves to Approved and remains visible via the All requests pane for a nice audit trail. As the requesting administrator, I need to return here to commit my change

Simply open the change, and then we can complete the request. Final confirmation of the changes to be made, and the approvers notes will also be visible to me.

Our request then moves to it’s final stage, completed!

In my test above, we’re looking at creating the actual approval policy. With this now enabled in my environment, attempting to change impacted policies within Intune I’ll now see the following:

Any attempts to save changes will now also show “Submit for approval”, rather than “Save” – it makes it very clear to the administrator making a change that further approval is needed.

What else do you need to know?

  • There is no additional licensing required for this feature
  • Only one approval for a configuration item can exist at one time – so you’ll need to consider this during periods of significant change
  • Approved changes finally need to be deployed by the original requestor – if working around change windows, try to get your approval phase done to have a change complete quickly when needed
  • Finally, everything is fully logged via usual Audit Log methods

This feature should be rolling out to all live environments over the coming weeks, if not already active in your tenant.

Related News

Helpful updates and insights from our team.

Ready to take the pain out of IT?

Let’s make IT the least stressful part of your business.

Whether you need outsourced IT support in London or nationwide coverage, we make IT simple, secure and predictable.