A cloud-based identity and access management service for securing user authentication and resource access
For Microsoft Entra PIM approvals, the supported behavior is:
- Go to Microsoft Entra admin center > ID Governance > Privileged Identity Management > Approve requests.
- Find the pending request.
- Enter a justification.
- Select Submit for Microsoft Entra roles, or Approve for Azure resource roles.
Relevant checks for the behavior described:
- Approvers can’t approve their own role activation requests. If the same account is both requester and approver, approval won’t complete as expected.
- Service principals can’t approve requests. Approval must be done by an eligible user approver.
- Approvals must be completed within 24 hours. If not approved in that window, the requester must submit a new request.
- Approval emails can be delayed. The first approval email is typically delivered within 3 to 10 minutes for 90% of cases, and for 1% of customers it can take up to 15 minutes. If one approver completes the approval in the portal before the first email is sent, other approvers might not receive the approval-request email.
If the portal shows the approval as successful but the request reappears, verify these first:
- The approver account is not the same account that requested activation.
- The approver is a user account, not a service principal.
- The request is still within the 24-hour approval window.
- Refresh Approve requests and confirm the current status there rather than relying on the email flow.
For Microsoft Entra role approvals, pending requests can also be checked with Microsoft Graph:
GET https://graph.microsoft.com/v1.0/roleManagement/directory/roleAssignmentScheduleRequests/filterByCurrentUser(on='approver')?$filter=status eq 'PendingApproval'
If the request still appears as pending there after an approval attempt, that confirms the approval did not persist.
References: