Ein Azure-Dienst für die präzise Zugriffsverwaltung für Azure-Ressourcen, mit dem Sie Benutzer*innen ausschließlich die Berechtigungen erteilen können, die sie für ihre Arbeit benötigen
Thank you for your response. We agree that an assignment should be processed without human approval when isApprovalRequiredForAdd is set to false. However, that is not the configuration in our scenario. We have already reproduced the issue multiple times with approval explicitly enabled. Our policy is deployed with the following settings:
- Approval is required for new assignments.
- approval_required = true in Terraform.
- An approval stage is configured.
- A security-enabled approver group with a direct member is configured.
- The approval timeout is 14 days.
- The Entra portal displays the configured approver group on the resulting assignment. We tested both policy scopes:
- NoSubjects, for administrator direct assignments only.
- AllExistingDirectoryMemberUsers, allowing internal users to request the package. For both configurations, a newly created app-only adminAdd request produced the same result:
- Submitted by the service principal.
- Auto-approved by Entra.
- Delivering.
- Access delivered. No approver took any action, no approval email was sent, and no pending request appeared in My Access. We also verified the effective caller configuration:
- The application uses app-only Workload Identity Federation.
- It does not have EntitlementManagement.ReadWrite.All.
- It does not have an Entra directory role.
- It does not have Catalog owner or Access package manager.
- It has only User.Read.All as a Microsoft Graph application permission.
- Its only intended Entitlement Management role is the catalog-scoped Access package assignment manager role. We repeated the test with multiple previously unassigned internal users. The result was consistently Auto-approved. Therefore, the scenario where approval is disabled has already been ruled out. The remaining question is specifically: Should an app-only adminAdd request honor an approval-required policy when the service principal has only the catalog-scoped Access package assignment manager role? The current Microsoft documentation states:
Access package assignment managers will no longer be able to bypass approval settings if the policy requires approval.
Our reproducible result contradicts that statement. If the expected behavior for app-only adminAdd differs from delegated administrator requests, could you please confirm that explicitly and point us to the relevant documentation? If this behavior is not documented, could this question be escalated to the Entra ID Governance product or documentation team?