In Azure AD, user consent and admin consent workflows control which users or administrators can approve access to organizational data requested by applications. The question states: * "Users can request admin consent to apps they are unable to consent to: Yes" * "Who can review admin consent requests: Admin2, User2" When User1 attempts to add an app that requires consent to access company data, and if that app requires admin consent, the request is routed to those designated as admin consent reviewers. In this case, Admin2 and User2 are listed, but only one has the administrative capability to approve the request. Based on Microsoft documentation: "Only users who hold an administrative role such as Global Administrator, Cloud Application Administrator, or Authentication Administrator and are designated as reviewers can grant consent on behalf of the organization." Here, Admin2 holds the Authentication Administrator role - an Azure AD admin-level role - while User2 has no administrative privileges. Thus, Admin2 is the only eligible user to approve the admin consent request.