Views:
  1. ISSUE BACKGROUND
    • You performed the configuration of Azure Active Directory mode integration and discovered the users and sent invitations.

      Trend Vision One Integration Settings

      Click the image to enlarge.

      Grant Trend Micro permission to access your Azure AD data

      Click the image to enlarge.

      Mobile Inventory

      Click the image to enlarge.

    • However, while enrolling with Mobile Security as a Service application from the agent and after login with region, email, and password, the "Need Admin Approval" error message pops up blocking the page.

      Need admin approval blocking page

      Click the image to enlarge.

  2. ROOT CAUSE   

    The error you encountered upon enrollment is caused by the User permission settings in the corporate MS Azure Active Directory. Please check the settings that can be found here: MS Azure Portal ==> All service ==> Enterprise applications ==> User settings == > User consent settings. If the config: User consent for applications, is set to Do not allow user consent as administrator will be required for all apps. The user invited from our Vision One Console does not grant/bind Global Administrator on Azure Active Directory, which is why you will encounter this problem.

       

    Enterprise Applications

    Click the image to enlarge.

    User Consent Settings

    Click the image to enlarge.

  3. SOLUTIONS       

    There are two options for the customer to do some changes on the Azure AD setting.

           
    • Option One:

      If the invited user account does not grant Global Administrator Role, it is recommended to do the user consent setting as flows:         

      MS Azure Portal ==> All service ==> Enterprise applications ==> User settings == > User consent settings, adding some permissions

      User settings>Consent and Permissions

      Click the image to enlarge.

      Allow user consent for Apps

      Click the image to enlarge.

      Add permissions

      Click the image to enlarge.

    • Option Two:

      If the invited user account does not assign the Global Administrator Role, assign Global Administrator Role to the user account, and the user consent setting can be set: "Do not allow user consent". An administrator will be required for all apps.

      Assigned Roles

      Click the image to enlarge.

      User consent for Applications

      Click the image to enlarge.