Admin: Application Settings Governance

Use Application Settings to define tenant-wide guardrails for new application requests, metadata quality, ownership requirements, and secret/certificate governance in AZExecute.


Governance Objectives

• Improve request quality with consistent metadata requirements

• Cap newly configured secret and certificate lifetimes when a maximum is set

• Require ownership coverage to prevent unmanaged applications

• Standardize environment and department classification

• Control application request approval behavior and optional TOPdesk ticket creation


Setting Areas

• General: enable app creation, approval flow, user import, all-application visibility, owner deletion, and credential lifetime limits

• Metadata: choose which request/edit fields are visible and which included fields are required

• Application Requests: route requests through a validated TOPdesk integration and configure create/approve/reject incident behavior

• Environments and Departments: maintain tenant picklists used by application metadata

• Ownership: set minimum co-owner count, notification target, and default administrators for newly created or imported applications

Default administrators are applied to new application records. Changing the list does not retroactively rewrite administrator assignments on existing applications.


Metadata Strategy

Start with a minimal required set, then expand mandatory fields as your governance maturity increases.

• Keep Business Justification required for all requests

• Require Environment and Department/Team for reporting and ownership routing

• Require Elevated Permissions Justification when elevated access is enabled

• Require Contact Email for operational follow-up and incident response

Review required-field impact with application owners before enforcing additional required metadata to avoid request friction.

Available Metadata Fields

• Core Context: Business Justification, Project Name, Department/Team, Environment, Business Criticality, Intended Audience, Expected Go-Live Date

• Requirements: Technical Requirements, Data Access Requirements

• Compliance & Contact: Compliance Notes, Requires Elevated Permissions, Elevated Permissions Justification, Contact Email, Contact Phone


Recommended Rollout

1. Configure settings in a maintenance window

2. Validate with test requests from a non-admin account

3. Announce changes to application owners and requesters

4. Revisit required metadata quarterly based on audit findings

Validation checklist: test a new application request, verify required-field validation, verify environment/department picklists, and confirm ownership defaults are applied as expected.

An unhandled error has occurred. Reload 🗙
An unhandled error has occurred. Reload 🗙