Plan for Change: Intune’s Multi Admin Approval will require approval for app-authenticated API requests
Microsoft announcement
[Introduction]
We recently enhanced Intune’s Multi Admin Approval (MAA) capability to include app-authenticated scenarios, ensuring that API calls made using app authentication are subject to the same dual-control approval and audit process as interactive admin actions. This also introduces a unified approval and auditing experience across both interactive admin actions and automated processes.
Your tenant is on an existing exclusion which will no longer be supported starting on July 27, 2026, or soon after, app-authenticated requests will require approval unless they are explicitly excluded through policy configuration.
[How this will affect your organization:]
Our telemetry indicates your tenant is on an existing exclusion which will no longer be supported after July 27, 2026. Exclusions must be configured at a per-app and per-workload level.
If your organization uses app-authenticated access with MAA-protected workloads, API requests made using application authentication will require approval through the MAA workflow before execution. Automation scenarios that rely on these requests may be blocked until an authorized admin completes the approval step.
[What you need to do to prepare:]
Before this change, review your current automations and update applications so they integrate with the MAA approval workflow, ensuring that requests are submitted for approval and reviewed by an authorized admin through interactive sign-in.
If needed, you can configure exclusions for specific applications using the updated self-service experience, applying them at the app and workload level through the MAA access policy.
After this change, review audit logs to monitor new MAA-related events to ensure expected behavior.
[Additional information:]
Use access policies to require multi admin approval
Change history
- 2026-07-15 · Created · All