Admin consent not applying for multi-tenant app

Oguz Gelal 5 Reputation points
2025-10-01T21:33:59.2466667+00:00

Hello!

We are experiencing an issue with our multi-tenant app.

Admin consent URL is being used correctly: https://login.microsoftonline.com/organizations/v2.0/adminconsent?client_id={CLIENT_ID}&redirect_uri={REDIRECT_URI}&scope=Mail.Send%20User.Read%20offline_access

Admin is a Global Administrator.

All required permissions are delegated (Mail.Send, User.Read, offline_access).

App is multi-tenant and the redirect URI is correctly registered.

Users still see repeated consent requests after admin approval, even in clean browsers.

We have verified that the admin has clicked the consent link, but the consent does not seem to apply properly for users.

Has anyone encountered this behavior, or is there a recommended way to ensure tenant-wide admin consent applies correctly for v2.0 multi-tenant apps?

Thank you for any guidance.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.