# Prepare the Intune approver group before protecting role changes

> Could an Intune role-protection policy prevent its own approval workflow from being configured?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:19+00:00
- Modified: 2026-09-10T02:11:18+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Could an Intune role-protection policy prevent its own approval workflow from being configured?

## Potentially affected

Apply this review when introducing the Role access-policy type. Inventory the requestor, approvers, existing role assignments, and any other protected resource types before enabling that protection.

## DSE recommendation

Complete and review the approval-group assignment first.

## Article

## Source facts

Intune Multi Admin Approval requires an approver non-mail-enabled security group directly assigned as a member group in an Intune RBAC role assignment; permissions held separately by individual members are insufficient. Approvers need direct group membership and the relevant resource-read permission. Microsoft warns that enabling protection for role changes before preparing these assignments can create a configuration deadlock. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/fundamentals/role-based-access-control/multi-admin-approval).

## Applicability

Apply this review when introducing the Role access-policy type. Inventory the requestor, approvers, existing role assignments, and any other protected resource types before enabling that protection.

## DSE recommendation

Complete and review the approval-group assignment first. Have a different administrator verify the exact group identifier, membership, and required read capability rather than relying on a familiar group name. Schedule role protection only after the team has proven its other approval paths. Document an authorized recovery escalation in advance without treating removal of protection as a routine workaround.

## Verification

Rehearse a permitted request with separate requestor and approver accounts. Microsoft requires the original requestor to select Complete after approval, so check the applied change rather than stopping at an approved status. Also verify that an unqualified account cannot approve and that the requestor cannot approve their own request. Keep the tested identities, resource scope, and outcome with the activation decision; do not infer readiness from group creation alone.

## Official references

[Microsoft Learn: Use Multi Admin Approval in Intune](https://learn.microsoft.com/en-us/intune/fundamentals/role-based-access-control/multi-admin-approval).

## Primary reference

- Name: Use Multi Admin Approval in Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/fundamentals/role-based-access-control/multi-admin-approval
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Prepare the Intune approver group before protecting role changes,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-517-prepare-the-intune-approver-group-before-protecting-role-changes/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
