{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes/",
        "slug": "dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes/"
        },
        "title": "Prepare the Intune approver group before protecting role changes",
        "summary": "Could an Intune role-protection policy prevent its own approval workflow from being configured?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:23:19+00:00",
        "modified_at": "2026-09-10T02:11:18+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 228,
        "potentially_affected": "Apply this review when introducing the Role access-policy type. Inventory the requestor, approvers, existing role assignments, and any other protected resource types before enabling that protection.",
        "dse_recommendation": "Complete and review the approval-group assignment first.",
        "primary_source": {
            "name": "Use Multi Admin Approval in Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/fundamentals/role-based-access-control/multi-admin-approval",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Intune Multi Admin Approval requires an approver non-mail-enabled security group directly assigned as a member group in an Intune RBAC role assignment; permissions held separately by individual members are insufficient. Approvers need direct group membership and the relevant resource-read permission. Microsoft warns that enabling protection for role changes before preparing these assignments can create a configuration deadlock. <a href=\"https://learn.microsoft.com/en-us/intune/fundamentals/role-based-access-control/multi-admin-approval\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Apply this review when introducing the Role access-policy type. Inventory the requestor, approvers, existing role assignments, and any other protected resource types before enabling that protection.</p>\n<h2>DSE recommendation</h2>\n<p>Complete and review the approval-group assignment first. Have a different administrator verify the exact group identifier, membership, and required read capability rather than relying on a familiar group name. Schedule role protection only after the team has proven its other approval paths. Document an authorized recovery escalation in advance without treating removal of protection as a routine workaround.</p>\n<h2>Verification</h2>\n<p>Rehearse a permitted request with separate requestor and approver accounts. Microsoft requires the original requestor to select Complete after approval, so check the applied change rather than stopping at an approved status. Also verify that an unqualified account cannot approve and that the requestor cannot approve their own request. Keep the tested identities, resource scope, and outcome with the activation decision; do not infer readiness from group creation alone.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/fundamentals/role-based-access-control/multi-admin-approval\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Use Multi Admin Approval in Intune</a>.</p>",
        "content_text": "Source facts\nIntune Multi Admin Approval requires an approver non-mail-enabled security group directly assigned as a member group in an Intune RBAC role assignment; permissions held separately by individual members are insufficient. Approvers need direct group membership and the relevant resource-read permission. Microsoft warns that enabling protection for role changes before preparing these assignments can create a configuration deadlock. Microsoft Learn.\nApplicability\nApply this review when introducing the Role access-policy type. Inventory the requestor, approvers, existing role assignments, and any other protected resource types before enabling that protection.\nDSE recommendation\nComplete and review the approval-group assignment first. Have a different administrator verify the exact group identifier, membership, and required read capability rather than relying on a familiar group name. Schedule role protection only after the team has proven its other approval paths. Document an authorized recovery escalation in advance without treating removal of protection as a routine workaround.\nVerification\nRehearse a permitted request with separate requestor and approver accounts. Microsoft requires the original requestor to select Complete after approval, so check the applied change rather than stopping at an approved status. Also verify that an unqualified account cannot approve and that the requestor cannot approve their own request. Keep the tested identities, resource scope, and outcome with the activation decision; do not infer readiness from group creation alone.\nOfficial references\nMicrosoft Learn: Use Multi Admin Approval in Intune.",
        "content_markdown": "## Source facts\n\nIntune Multi Admin Approval requires an approver non-mail-enabled security group directly assigned as a member group in an Intune RBAC role assignment; permissions held separately by individual members are insufficient. Approvers need direct group membership and the relevant resource-read permission. Microsoft warns that enabling protection for role changes before preparing these assignments can create a configuration deadlock. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/fundamentals/role-based-access-control/multi-admin-approval).\n\n## Applicability\n\nApply this review when introducing the Role access-policy type. Inventory the requestor, approvers, existing role assignments, and any other protected resource types before enabling that protection.\n\n## DSE recommendation\n\nComplete and review the approval-group assignment first. Have a different administrator verify the exact group identifier, membership, and required read capability rather than relying on a familiar group name. Schedule role protection only after the team has proven its other approval paths. Document an authorized recovery escalation in advance without treating removal of protection as a routine workaround.\n\n## Verification\n\nRehearse a permitted request with separate requestor and approver accounts. Microsoft requires the original requestor to select Complete after approval, so check the applied change rather than stopping at an approved status. Also verify that an unqualified account cannot approve and that the requestor cannot approve their own request. Keep the tested identities, resource scope, and outcome with the activation decision; do not infer readiness from group creation alone.\n\n## Official references\n\n[Microsoft Learn: Use Multi Admin Approval in Intune](https://learn.microsoft.com/en-us/intune/fundamentals/role-based-access-control/multi-admin-approval)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Prepare the Intune approver group before protecting role changes",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes/",
                "headline": "Prepare the Intune approver group before protecting role changes",
                "description": "Could an Intune role-protection policy prevent its own approval workflow from being configured?",
                "abstract": "Could an Intune role-protection policy prevent its own approval workflow from being configured?",
                "articleBody": "Source facts\nIntune Multi Admin Approval requires an approver non-mail-enabled security group directly assigned as a member group in an Intune RBAC role assignment; permissions held separately by individual members are insufficient. Approvers need direct group membership and the relevant resource-read permission. Microsoft warns that enabling protection for role changes before preparing these assignments can create a configuration deadlock. Microsoft Learn.\nApplicability\nApply this review when introducing the Role access-policy type. Inventory the requestor, approvers, existing role assignments, and any other protected resource types before enabling that protection.\nDSE recommendation\nComplete and review the approval-group assignment first. Have a different administrator verify the exact group identifier, membership, and required read capability rather than relying on a familiar group name. Schedule role protection only after the team has proven its other approval paths. Document an authorized recovery escalation in advance without treating removal of protection as a routine workaround.\nVerification\nRehearse a permitted request with separate requestor and approver accounts. Microsoft requires the original requestor to select Complete after approval, so check the applied change rather than stopping at an approved status. Also verify that an unqualified account cannot approve and that the requestor cannot approve their own request. Keep the tested identities, resource scope, and outcome with the activation decision; do not infer readiness from group creation alone.\nOfficial references\nMicrosoft Learn: Use Multi Admin Approval in Intune.",
                "datePublished": "2026-09-10T00:23:19+00:00",
                "dateModified": "2026-09-10T02:11:18+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Prepare the Intune approver group before protecting role changes"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 228,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use Multi Admin Approval in Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/fundamentals/role-based-access-control/multi-admin-approval"
                }
            }
        ]
    }
}