Videos
We have multiple users using apps like pipedrive and calendly and currently have it set to disable users connecting without admin approval which makes for potentially a lot of manual approvals from us.
We also may not necessarily have enterprise activations for all of these so SSO/SCIM is not feasible.
I'm working on a change request prior to implementation and it seems like there's a few scenarios to choose such as:
users needing no apporoval (bad and not doing it)
Auto grant/deploy users in a list access to the apps
Create approved list and users have to opt in but will not get any pushback from the environment
Users are denied access until they send in a request which admins have to audit.
Does anyone have any better resources that explains the pros and cons of each and how to implmenet than the fragmented Microsoft docs?
https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/configure-user-consent?tabs=azure-portal
https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/grant-admin-consent