A harbor-operations API needs every employee to use reviewed scopes without a per-user consent prompt. Which consent action should the security engineer take?
Select an answer to reveal the explanation.
Short Explanation
Once the scopes are reviewed, one tenant-wide admin consent lights the green lamp for the whole directory—no clipboard scavenger hunt of adminconsent links on every desk. Pair it with assignment required if you still want a boarding list.
Full Explanation
Tenant-wide admin consent grants the requested permissions for all users in the tenant, eliminating repeated per-user consent prompts after scopes are approved. Engineers should still understand that broad consent covers the directory unless user assignment required further restricts who can use the app. Distributing adminconsent URLs to every workstation is operationally fragile and unnecessary after a proper admin consent grant. Key Vault roles and Security Copilot do not perform Entra admin consent.