A third-party app may show a Microsoft consent screen requesting mailbox, files or other organization data. Admin consent can grant the app access for more than one employee. Even a useful app deserves a deliberate review of publisher, permissions and the business need.
Before you start
Ask the requester for the app's exact name, publisher, link, business owner and task. Use your organization's normal app review process; a sign-in prompt alone is not an approval ticket.Do it step by step
- Open the request through the Microsoft Entra admin center or your documented workflow, not solely through an emailed consent link.
- Confirm the application identity and publisher. Compare them with the vendor and integration described by the business owner; a verified publisher badge is a signal, not a guarantee.
- Read every requested delegated and application permission. Determine whether the app needs the requested scope, especially broad access to mail, files or all users.
- Check who will own the integration, what data it will retain and how access will be removed. Prefer a narrower approved option if the task does not require tenant-wide access.
- Record the decision. Deny or defer unclear requests; approve only through the authorized admin role and recheck the resulting permissions and assigned users.