---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Require approval for agent-based Office 365 group membership changes \[New in Security Center 7.0\]

# Require approval for agent-based Office 365 group membership changes \[New in Security Center 7.0\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Enable the approval flow for adding or removing Office 365 group members through the Microsoft 365 group membership AI Agent using a system property.
Use the sn_itsm_aia.office_365_group_member_approval.required system property to control whether the approval flow for adding or removing Office 365 group members through the AI agent is on or off. When the
approval workflow is enabled, an approval record must be set to approved by a member of the group specified in the sn_itsm_aia.office_365_group_member_approval.group_id system property. If the
sn_itsm_aia.office_365_group_member_approval.group_id property isn't configured, the Microsoft 365 group member approvers group is used.

## More information {#sc-require-approval-for-agent-based-office-365-group-membership-changes__section_lnh_pkf_32c}

{#sc-require-approval-for-agent-based-office-365-group-membership-changes__table_hhv_dvg_1xb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | sn_itsm_aia.office_365_group_member_approval.required |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | true |
| Default value | true |
| Fallback value | true |
| Category | [Access control](https://servicenow-prod.fluidtopics.net/xAmazkRh5FKyeb7q4TQGWw "The access control category audits the process of protecting resources from unauthorized access through granting and denying requests based on a permission model. This includes ensuring an entity accessing a resource holds valid credentials to do so, creating and protecting a well-defined set of roles or permissions and ensuring role or permission controls are protected from replay and tampering.") |
| Security risk | * Severity score: 4.9 * CVSS score: Medium * Any user who can access the Microsoft 365 group membership AI Agent can and add and remove Office 365 group members from the Azure AD group if explicit approval from the specified approvers group isn't required. Ensure that these changes are approved to reduce the risk of elevation of privilege by adding/removing members without proper authorization. {#sc-require-approval-for-agent-based-office-365-group-membership-changes__ul_ihv_dvg_1xb} |
| Functional impact | When sn_itsm_aia.office_365_group_member_approval.required is set to true, a member of the group specified in sn_itsm_aia.office_365_group_member_approval.\<group_id\> must approve the Incident requesting addition or removal of Office 365 group members. If sn_itsm_aia.office_365_group_member_approval.required is set to false then no approval is required and the AI Agent can autonomously handle the process of adding or removing members from an Office 365 group. |
| Dependencies and prerequisites | None |
[ ]

{#sc-require-approval-for-agent-based-office-365-group-membership-changes__table_hhv_dvg_1xb}

To learn more about adding or creating a system
property, see [Add a system property](https://www.servicenow.com/docs/access?context=t_AddAPropertyUsingSysPropsList&version=australia&pubname=australia-platform-administration&ft:locale=en-US).

