Admin consent and org-wide app grants in Microsoft 365, explained
Admin consent in Microsoft 365 is when an administrator approves a third-party app’s permissions on behalf of the entire organization — one click that can give the app access to every mailbox and file in the tenant. It’s the mechanism behind your most consequential app grants, and behind “illicit consent” phishing, where an attacker’s app tricks a busy admin into approving org-wide access. Here’s how it works and how to review what’s been granted.
User consent vs. admin consent
When an app requests permissions, one of two things happens. For low-risk delegated permissions, a regular user can consent for themselves. For higher-risk permissions — or any application permission that acts tenant-wide — an administrator must consent, and that consent can be granted on behalf of the whole organization. That org-wide grant is the one to watch: it applies to every user at once, not just the person who clicked.
Why org-wide grants are the real risk
- Blast radius. An application permission like Mail.Read or Files.ReadWrite.All, admin-consented org-wide, reaches every mailbox or file — not one user’s.
- Illicit consent phishing. Attackers register a plausible-looking app and trick an admin into granting it. No password is stolen; the app simply keeps the access it was given.
- User consent left wide open. If users are allowed to consent to any app for any permission, risky grants accumulate without an admin ever seeing them. Most tenants should restrict user consent to verified publishers and low-risk scopes.
- Consent doesn’t expire. An org-wide grant stays until someone revokes it, long after anyone remembers approving it.
How to review it
In the Microsoft Entra admin center, each app under Enterprise applications → Permissions shows what was admin-consented and whether it was granted for the whole organization. Under Enterprise applications → Consent and permissions you can tighten the user consent settings and configure an admin consent workflow so requests are reviewed rather than rubber-stamped. Prioritize broad, org-wide grants held by unverified publishers.
A faster path
Esmeris surfaces exactly these grants: a read-only audit that separates org-wide admin-consented access from per-user consent, flags broad scopes and unverified publishers, and ranks them in a graded report. See the sample report for what that looks like.