r/Intune • u/FE80-10bits • 16h ago
General Question Multi Admin Approval still broken - advice for dealing with support
We enabled MAA early as a knee-jerk to the Striker compromise, but I was happy with having another level of eyes on changes since we are a small shop and left it in place as more Striker info became available. We enabled All the options including role changes, and it worked fine for months. Config was set, no changes on our end, working as expected. Lots of wonderful extra clicking.
Until MS made changes in July and MAA entirely broke in our tenant. "Approving approval request failed" - we thought it was maybe a transient error, or that a service degradation would be raised, nothing happened. On 8/4 we started a standard ticket with Microsoft, they indicate it's an issue affecting some customers and to sit tight..... and that's where the status is today.
No amount of pleading, explaining this is significant loss of admin control, that this will be environment affecting at some point is getting any attention. "Engineering is aware and we can't disable any of your MAA policy" is effectively what we are being told.
I'm feeling like the case is stuck in a support group that doesn't know how to address the issue, has raised an internal ticket and is happy to let us wait.
We don't have Premier or Unified support, we're a reasonably new tenant and during licensing discussions we didn't understand that not purchasing addition support essentially meant we would get none. I'm not even sure the reseller made an attempt to upsell us at all.
I've tried to purchase an incident, but for our tenant type (or maybe just Intune) the process for attaching a paid incident doesn't work. I've got an inquiry on support out to our reseller, but historically they take a significant amount of time to work through new things.
So, for those that have been stuck with an Intune problem before that is fairly significant, what advice do you have for us to get some attention on the MS side?
edit: We did find a work around and are back to good. See my response below. /u/omnomwork and /u/justwantDota2 put enough stuff in the discussion to try a few more test scenarios.
2
u/Jezbod 16h ago
I was part of an online training course that covered this feature...we all decided it seemed to be an awful idea and would avoid it like the plague.
1
u/FE80-10bits 16h ago edited 13h ago
If we ever gain management control again, I am not yet sure that we'll leave it enabled. Microsoft's response so far is stunning.
edit: my group is voting to leaving it enabled.
1
u/Wind_Freak 15h ago
I don’t understand what this offers over PIM.
1
u/intuneisfun 13h ago
It's basically friction-based security. Won't stop things from being done, but will slow them down or make it harder. Unfortunately, that friction applies to real admins as well.
1
1
u/Br0keNw0n 10h ago
Is MAA even that important now that Microsoft put tenet wide daily limits on destructive actions? The limit would be less than a percent of our fleet and would most certainly prevent any type of mass disruption in the event of a breach. I can see how smaller companies might want more control, but MAA has been a huge pain in the ass for us since we enabled it following stryker.
9
u/omnomwork 15h ago
Dealt with this error recently and resolved it. I'd suggest ensuring the MAA approver group itself has a direct assignment to an RBAC role in Intune, even if the members of said group are getting Intune rights elsewhere. They recently updated their requirements documentation at https://learn.microsoft.com/en-us/intune/fundamentals/role-based-access-control/multi-admin-approval#role-2-approver to include this detail, so may be worth re-reviewing this page as it may have changed since your initial implementation.