If you are in the U.S. region, once you select Tenants and click Add Tenant, you must select the type of tenant you are adding, whether commercial, GCC, or GCC High. When you click Add Commercial or GCC Tenant (or Add GCC High Tenant) you are redirected to the Microsoft tenant administration login page where you must log in with the Global Administrator credentials for the tenant.
If you are in any other region, you select Add Tenant and are immediately redirected to the Microsoft tenant administration login page where you must log in with the Global Administrator credentials for the tenant. After successful authentication, the Consent Grant dialog is displayed. You must confirm the consent grant.
GCC or a GCC High tenants are available only for deployments in the U.S. region.
2 |
3 |
Click Add Tenant. |
• |
Click Add Commercial or GCC Tenant |
6 |
Click Accept. |
7 |
8 |
If the minimum permission settings granted when the tenant was added are sufficient for a module, the Status for the module is Uses Base. If the module requires additional permissions, the Status is Not Granted. |
10 |
Click Accept. |
Once you add a tenant, you are redirected to a page that lists the permissions that will be granted. You must click Accept and provide admin consent for the On Demand application. Once the Global Administrator adds a tenant to On Demand, an application record is created in the tenant indicating that admin consent has been provided.
On May 19, 2022, On Demand introduced a new consent experience using Microsoft Authentication Library (MSAL) which required that consent be regranted for modules that use delegated permissions. For details about MSAL, see About the Microsoft Authentication Library (MSAL) .
To open the Tenant Consents page, click Tenants in the navigation page and click Edit Consents on the tenant tile.
You can view the specific permissions for each On Demand application by clicking View Details. You can also see the last time that consent was granted and which On Demand user granted the consent.
For some consent types, you might also have to assign a role after you grant consent.
1 |
Click Tenants in the navigation panel on the left. |
2 |
At the bottom of a tenant tile, click Edit Consents. |
3 |
If the current status is Not Granted, you can enable the module consent type for this tenant by clicking Grant Consent. |
For the following scenarios, you would click Grant Consent or Regrant Consent in the Status and Actions column.
• |
The admin consent token for the module expired, resulting is a status of Consent Required. The status of Consent Required indicates that On Demand cannot obtain a token with delegated permissions based on a previously granted admin consent. To restore the interrupted services, you must regrant consent. |
• |
A new feature in an On Demand module can require that additional permissions be granted. In this scenario, you would click Regrant Consent. For example, when On Demand implemented the new Microsoft Authentication Library (MSAL) in June 2022, admin consents had to be regranted for modules that use delegated permissions. |
• |
Admin consent has been revoked in the Azure AD portal, resulting in a status of Revoked. If you revoke the Core Basic admin consent in the tenant you will see Revoked status for Core Basic and Not Available for all other modules. The Core Basic application is used to determine the consent status for your tenant. If that consent is revoked, On Demand cannot determine consent status for the rest of the modules. Consent might be granted for the modules, but On Demand cannot verify it. |
This feature provides a more secure and granular approach for accessing your data. For more information, see Permissions and consent in the Microsoft identity platform.
1 |
Install the Azure PowerShell Az module if it is not already installed. |
© 2023 Quest Software Inc. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy Cookie Preference Center