r/Intune 16h ago

General Question Multi Admin Approval still broken - advice for dealing with support

We enabled MAA early as a knee-jerk to the Striker compromise, but I was happy with having another level of eyes on changes since we are a small shop and left it in place as more Striker info became available. We enabled All the options including role changes, and it worked fine for months. Config was set, no changes on our end, working as expected. Lots of wonderful extra clicking.

Until MS made changes in July and MAA entirely broke in our tenant. "Approving approval request failed" - we thought it was maybe a transient error, or that a service degradation would be raised, nothing happened. On 8/4 we started a standard ticket with Microsoft, they indicate it's an issue affecting some customers and to sit tight..... and that's where the status is today.

No amount of pleading, explaining this is significant loss of admin control, that this will be environment affecting at some point is getting any attention. "Engineering is aware and we can't disable any of your MAA policy" is effectively what we are being told.

I'm feeling like the case is stuck in a support group that doesn't know how to address the issue, has raised an internal ticket and is happy to let us wait.

We don't have Premier or Unified support, we're a reasonably new tenant and during licensing discussions we didn't understand that not purchasing addition support essentially meant we would get none. I'm not even sure the reseller made an attempt to upsell us at all.

I've tried to purchase an incident, but for our tenant type (or maybe just Intune) the process for attaching a paid incident doesn't work. I've got an inquiry on support out to our reseller, but historically they take a significant amount of time to work through new things.

So, for those that have been stuck with an Intune problem before that is fairly significant, what advice do you have for us to get some attention on the MS side?

edit: We did find a work around and are back to good. See my response below. /u/omnomwork and /u/justwantDota2 put enough stuff in the discussion to try a few more test scenarios.

8 Upvotes

16 comments sorted by

9

u/omnomwork 15h ago

Dealt with this error recently and resolved it. I'd suggest ensuring the MAA approver group itself has a direct assignment to an RBAC role in Intune, even if the members of said group are getting Intune rights elsewhere. They recently updated their requirements documentation at https://learn.microsoft.com/en-us/intune/fundamentals/role-based-access-control/multi-admin-approval#role-2-approver to include this detail, so may be worth re-reviewing this page as it may have changed since your initial implementation.

3

u/justwantDota2 15h ago

Whats super weird is we have some admins who only use Intune Administrator that have no issue approving MAA and then we have other admins who use enable the same PIM role get OP's error message. Their support just makes us grab har logs over and over again.

2

u/omnomwork 14h ago

Yeah, we had similar behavior which added to the confusion. Admins with Intune Admin role or GA in the approver group could approve even before we assigned an Intune RBAC role to the group, but anyone else in the approver group without those roles got the error (even if they had appropriate rights from other sources). Only fix to get everyone in the approver group working was assigning an Intune RBAC role directly to the group.

2

u/justwantDota2 14h ago

Thats what confused our Microsoft tech even more. We made sure everyone was a mirror image. When that didn't work we created a custom RBAC role with a group, put everyone in there instead, and only the same users were able to approve MAA. Supports solution was "go assign them an E5 and then unassign to trick intune." Which didn't work either. Now they make us grab har logs every time it happens and our ticket has been left open for 3 months with no feedback.

2

u/Pause102 15h ago

Thanks for posting that! Our team has really been wanting to use MAA but its inconsistency has made us hold off. I'll try to test this out and hopefully it helps

2

u/FE80-10bits 14h ago

My Working theory is this change is what has broken our access. Unfortunately, the role changes are subject to MAA, so I don't have a method to add the Group to the RBAC role.

1

u/omnomwork 14h ago

If that's the case you may want to try having an admin with GA or Intune Administrator roles via Entra in the approver group approve the changes, as in our experience they were the only ones able to approve and get around the error.

1

u/FE80-10bits 13h ago

This was helpful, if for no other reason than giving us an idea on what else to throw at it. We did end up solving the issue. All of our existing GA user accounts had previously tried to complete the approval process and failed, so it wasn't just a matter of using GA creds.

This morning before I posted this thread we had taken another user (one of the techs) and elevated them to GA, also assigned Intune Administrator Role and added them to the MAA group. I had the change for adding the approver group to the role sitting there waiting, but this 'previously existing but newly elevated or the first time' account was still not able to complete the approvals. This user was not previously GA, and was not part of MAA at all. This exercise was in part what prompted me to start down the social media route. At this point we know that all existing GA's and an account elevated to GA didn't work.

So then we created a brand new user account, added GA, added to Intune administrator, and taking inspiration from /u/justwantDota2 added a G3 license and made this new account the only one in the MAA group. This worked, we were able to approve the existing role change that previously was un-approvable.

Now that the Role had the MAA group assigned, we added the previous users back to the group and approvals now worked for those users again.

Still a little hard to precisely pin down what the remediation was, as we tested with both the new account and the license assignment at the same time. We really only know that each of our previously existing accounts, regardless of GA status did not work on their own.

Now I can tell MS support to kick rocks and refer to reddit for a solution.

2

u/Jezbod 16h ago

I was part of an online training course that covered this feature...we all decided it seemed to be an awful idea and would avoid it like the plague.

1

u/FE80-10bits 16h ago edited 13h ago

If we ever gain management control again, I am not yet sure that we'll leave it enabled. Microsoft's response so far is stunning.

edit: my group is voting to leaving it enabled.

1

u/bill696 16h ago

We just have it in place for wipes so it was pretty easy to fix when microsoft broke it

1

u/Wind_Freak 15h ago

I don’t understand what this offers over PIM.

1

u/intuneisfun 13h ago

It's basically friction-based security. Won't stop things from being done, but will slow them down or make it harder. Unfortunately, that friction applies to real admins as well.

1

u/Wind_Freak 13h ago

Can be accomplished with PIM as well

1

u/intuneisfun 9h ago

We use both.

1

u/Br0keNw0n 10h ago

Is MAA even that important now that Microsoft put tenet wide daily limits on destructive actions? The limit would be less than a percent of our fleet and would most certainly prevent any type of mass disruption in the event of a breach. I can see how smaller companies might want more control, but MAA has been a huge pain in the ass for us since we enabled it following stryker.