A tenant has disabled user consent and is enabling the admin consent workflow so employees can request access to applications they cannot consent to. The security team insists that the people who approve these consent requests must be able to actually grant tenant-wide consent on behalf of the organisation. Which role must the designated reviewers hold for their approvals to take effect?
- AReports Reader, so reviewers can read the consent request telemetry before approving each application
- BA role able to grant tenant-wide consent, such as Cloud Application Administrator, Application Administrator, or Global Administrator Correct
- CGroups Administrator, so reviewers can assign the approved application to the requesting user's groups
- DHelpdesk Administrator, since approving consent requests is treated as a routine user support task
Why A is wrong: Reports Reader only grants read access to reports and sign-in data; it confers no ability to grant consent, so a reviewer with this role could not action a request.
Why B is correct: Granting consent on behalf of the organisation requires permission to consent to applications, which Cloud Application Administrator, Application Administrator, and Global Administrator provide, so designated reviewers must hold one of these.
Why C is wrong: Groups Administrator manages group membership and has no rights over application consent, so a reviewer with only this role could not grant the requested permissions.
Why D is wrong: Helpdesk Administrator covers password resets and limited user support and cannot grant application consent, so approvals from a reviewer holding only this role would fail.