Troubleshoot Intune Multi Admin Approval blocking Nerdio Manager tasks

Since the week of June 15 2026, Intune Multi Admin Approval (MAA) enforcement covers application-authenticated Microsoft Graph calls as well as interactive admin actions. Nerdio Manager manages Intune through Graph, so writes to a resource protected by an MAA access policy fail until the change is approved in Intune.

Symptoms

In a tenant with MAA access policies configured, Nerdio Manager write operations fail. Affected tasks include:

  • Creating, editing, assigning, or deleting policies in Endpoints > Intune > Policy Management

  • Deploying UAM applications to Intune devices

  • Retire, Wipe, and Delete on Endpoints > Intune > All Devices

  • Intune script tasks

  • Automatic AVD device record cleanup

The task reports an HTTP error whose response body names Multi Admin Approval.

Caution

Microsoft's documentation gives conflicting status codes — 403 in the Intune what's-new entry, 400 in the Graph API guidance. Match on the message, not the code.

Note

MAA affects only operations that modify a protected resource (POST, PATCH, PUT, DELETE); reads are never affected. If dashboards, device lists, policy reports and Insights: Intune still populate while only writes fail, suspect MAA.

Cause

  • Cause: an MAA access policy protects the resource Nerdio Manager is modifying, so Intune holds the change pending approval. Nerdio Manager does not implement the MAA workflow — it sends no x-msft-approval-justification header and does not resubmit with an approval code — so the call fails.

  • Recommendation: exclude the Nerdio Manager application from each access policy. This works only in Application context (all actions) and Application & user context modes (Nerdio Automated tasks only), because Intune exclusions apply solely to app-auth calls; delegated calls stay enforced.

Mode

Availability

Detail

Application context

Workaround

Exclude the Nerdio Manager application from each access policy. This will prevent the MAA block.

Application & user context

Partial workaround

Exclude the Nerdio Manager application from each access policy. The exclusion covers Intune API calls initiated by the Nerdio Manager application only. Delegated calls will still be blocked. Verify against your own policies.

User context

No workaround

Delegated calls cannot be excluded. Change the process or the mode.

Note

MAA is opt-in per workload, and this change applies only to tenants that already have access policies configured. With no active policies, nothing is affected.

Affected Nerdio Manager features

All create, edit, assign and delete operations against these resources are affected. Policy tabs sit under Endpoints > Intune > Policy Management.

Profile type

Nerdio Manager functionality blocked

Apps

UAM application deployment to Intune devices; the Applications tab. Excludes app protection policies.

Compliance policies

The Compliance Policies tab.

Configuration policies

The Configuration Profiles tab. Microsoft scopes this type to the settings catalog, so Security Baselines and Windows Update may fall outside it; Conditional Access is Entra ID and is never covered.

Device actions

Retire, Wipe and Delete on All Devices; AVD device record cleanup (Features:AvdHostEntraIdCleanup), which deletes Intune device records.

Scripts

Intune script tasks. UAM deployment to Intune devices depends on Intune script permissions, so this can block UAM deployment too.

Role-based access control

Not expected to affect Nerdio Manager — no documented Intune RBAC management.

Tenant Configuration

Not expected to affect Nerdio Manager — no documented device category management.

Note

Further access policy rules can be created through Graph for resource types absent from the admin center, such as app protection and endpoint security policies. If a write fails against a resource type not listed above, review your full policy set through Graph before opening a ticket.

Confirm that Multi Admin Approval is the cause

To check for active MAA access policies

  1. In the Microsoft Intune admin center, go to Tenant administration > Multi Admin Approval > Access policies.

  2. Note each policy's Profile type. An empty list means MAA is not enabled and is not your cause.

  3. Under All requests, look for requests raised when the Nerdio Manager task failed. MAA events — approve, block, pass and exclusion changes — are also recorded in the Intune audit log.

To determine your Intune operation mode

  1. In Nerdio Manager, go to System > Settings.

  2. In the Integrations area, expand Intune.

  3. Scroll to Mode. The value shown is the current operation mode.

For a full description of each mode, see Enable and configure Intune.

Application & user context modes

In these modes Nerdio Manager writes to Intune with an app-only token issued to its own enterprise application, so you can exclude that application per access policy.

Caution

Excluding an application bypasses MAA for that resource type, creating a gap that could be exploited if the application is compromised. Clear it with your change management and security teams, and review your exclusions regularly.

To identify the Nerdio Manager application

  1. In the Microsoft Entra admin center, expand App Registrations and locate nerdio-nmw-app — the default name of the Nerdio Manager primary app registration, which may have been renamed during an advanced installation.

  2. Record the Application (client) ID.

Note

The registration is multitenant. Where Nerdio Manager manages several Entra ID tenants it lives in the install tenant, and a service principal with the same Application (client) ID exists in each consented tenant — search the managed tenant's enterprise applications by that ID.

To exclude the Nerdio Manager application from an access policy

  1. Sign in to the Intune admin center with an account that can manage access policies, and go to Tenant administration > Multi Admin Approval > Access policies.

  2. Open and edit the policy whose profile type covers the blocked functionality.

  3. On the Exclusions tab, under Apps, add the Nerdio Manager application.

  4. On Review + submit for approval, enter a Business justification and select Submit for approval.

  5. Have a second administrator from the policy's approver group approve it under Received requests.

  6. Sign back in as the submitter, open the policy and select Complete. The exclusion takes effect only after this step.

  7. Repeat for every access policy protecting a resource Nerdio Manager writes to.

Caution

If nobody can approve, check the approver group itself. Intune requires a security group, directly assigned to an Intune RBAC role as a member group, with direct user members. Distribution lists, Microsoft 365 groups and mail-enabled security groups fail silently, and nested membership is unreliable.

Note

Nobody can approve their own request, even as an approver-group member.

Requests not processed within 3 days expire and must be resubmitted.

Exclusions apply only to the policy carrying them, and are capped at 50 applications per policy.

Exclusion changes are captured in the Intune audit log.

Application & user context mode

Here Nerdio Manager runs primarily in application context, using a linked Intune service account's delegated permissions for a few operations — chiefly BitLocker key retrieval and other privileged operations. The exclusion covers the app-auth writes above; any write made through the linked account stays subject to MAA and cannot be excluded, so verify against your own policies.

User context mode

Warning

No workaround exists for User context mode. Intune exclusions apply only to app-auth calls, so an integration acting for the signed-in admin remains enforced.

Consider these options instead.

  • Make the change in Intune. The native MAA workflow captures the justification, routes it to an approver and completes it. Nerdio Manager's read-only views catch up at the next data refresh.

  • Narrow your access policies. Drop profile types where change control can be met another way — for example Nerdio Manager's own policy approval requests. See Intune policies and configurations.

  • Switch to Application context or Application & user context mode, which makes exclusion available. This changes the permission set and the available features, so review Enable and configure Intune and Intune: Granular permissions first, and clear it with your security team.

Nerdio Manager approvals and Intune Multi Admin Approval are separate

The two are independent mechanisms with different approvers. Nerdio Manager policy approval requests go to another Nerdio Manager user holding approval permissions (see Review and approve policy changes in Intune policies and configurations); Intune MAA requests go to the Entra ID approver group on the access policy.

Where both are enabled, a change approved in Nerdio Manager is still submitted to Graph and still subject to MAA, so Nerdio Manager approval alone is not expected to be sufficient. Pending Intune MAA requests are not surfaced in Nerdio Manager.

Verify the resolution

  1. In the Intune portal, confirm the policy lists the Nerdio Manager application under Exclusions and is no longer pending approval.

  2. Retry the failed write in Nerdio Manager - for example, save a configuration profile, or deploy a UAM application to one test device.

  3. Confirm the Nerdio Manager task log shows no Graph API error.

  4. Confirm the Intune audit log records the call as passed, not blocked.

Planned support

Full MAA interoperability is on the Nerdio Manager roadmap:

  • indicators on entities with a pending Intune approval request

  • edit prevention on entities locked by a pending Intune approval request

  • prompting for requester notes and sending them in the justification header

  • Intune approval requests and access policies shown alongside those generated by Nerdio Manager.

Contact your Nerdio account team for timelines.

Note

If neither the exclusion nor the alternatives above are viable, raise a support ticket with your Installation ID, your Intune operation mode, and your active access policy profile types.

Was this article helpful?

0 out of 0 found this helpful
Have more questions? Submit a request

Comments (0 comments)

Article is closed for comments.