← All resources

Admin consent and org-wide app grants in Microsoft 365, explained

Admin consent in Microsoft 365 is when an administrator approves a third-party app’s permissions on behalf of the entire organization: one click that can give the app access to every mailbox and file in the tenant. It’s the mechanism behind your most consequential app grants, and behind “illicit consent” phishing, where an attacker’s app tricks a busy admin into approving org-wide access. Here’s how it works and how to review what’s been granted.

What does “consent on behalf of your organization” mean?

If a sign-in prompt shows a checkbox that says “Consent on behalf of your organization”, you’re looking at admin consent. Ticking it approves the app’s requested permissions for every user in the tenant, not just yourself. Only administrators see the option, and the users it covers never see a consent screen at all, so treat it as a change-control decision, not a login step.

User consent vs. admin consent

When an app requests permissions, one of two things happens. For low-risk delegated permissions, a regular user can consent for themselves. For higher-risk permissions, or any application permission that acts tenant-wide, an administrator must consent, and that consent can be granted on behalf of the whole organization. That org-wide grant is the one to watch. It applies to every user at once, including people who never saw a consent screen.

Why org-wide grants are the real risk

  • Blast radius. An application permission like Mail.Read or Files.ReadWrite.All, admin-consented org-wide, reaches every mailbox or file in the tenant.
  • Illicit consent phishing. Attackers register a plausible-looking app and trick an admin into granting it. No password gets stolen. The app keeps the access it was given.
  • User consent left wide open. If users are allowed to consent to any app for any permission, risky grants accumulate without an admin ever seeing them. Most tenants should restrict user consent to verified publishers and low-risk scopes.
  • Consent doesn’t expire. An org-wide grant stays until someone revokes it, long after anyone remembers approving it.

How to review it

In the Microsoft Entra admin center, each app under Enterprise applications → Permissions shows what was admin-consented and whether it was granted for the whole organization. Under Enterprise applications → Consent and permissions you can tighten the user consent settings and configure an admin consent workflow so requests get a review before approval. Prioritize broad, org-wide grants held by unverified publishers.

A faster path

Esmeris surfaces these grants for you. A read-only audit separates org-wide admin consent from per-user consent and flags the broad scopes and unverified publishers, ranked in a graded report.

Start your free audit