🛡️ Microsoft Entra ID User Consent For Applications is not set to Allow From Verified Publishers🟢⚪
- Contextual name: 🛡️ User Consent For Applications is not set to Allow From Verified Publishers🟢⚪
- ID:
/ce/ca/azure/microsoft-entra-id/allow-user-consent-for-applications-from-verified-publishers - Tags:
- Policy Type:
BEST_PRACTICE - Policy Categories:
SECURITY
Similar Policies
- Cloud Conformity: Users Can Consent To Apps Accessing Company Data On Their Behalf
Description
Description
Allow users to provide consent for selected permissions when a request is coming from a verified publisher.
Rationale
If Microsoft Entra ID is running as an identity provider for third-party applications, permissions and consent should be limited to administrators or pre-approved. Malicious applications may attempt to exfiltrate data or abuse privileged user accounts.
Impact
Enforcing this setting may create additional requests that administrators need to review.
Audit
From Azure Portal
- From Azure Home select the Portal Menu.
- Select
Microsoft Entra ID.- Under
Manage, selectEnterprise applications.- Under
Security, selectConsent and permissions.- Under
Manage, selectUser consent settings.- Under
User consent for applications, ensureAllow user consent for apps from verified publishers, for selected permissionsis selected.From PowerShell
Connect-MgGraph (Get-MgPolicyAuthorizationPolicy).DefaultUserRolePermissions | Select-Object -ExpandProperty PermissionGrantPoliciesAssigned
... [see more](description.md)
Remediation
Remediation
From Azure Portal
- From Azure Home select the Portal Menu.
- Select
Microsoft Entra ID.- Under
Manage, selectEnterprise applications.- Under
Security, selectConsent and permissions.- Under
Manage, selectUser consent settings.- Under
User consent for applications, selectAllow user consent for apps from verified publishers, for selected permissions.- Select
Save.
policy.yaml
Linked Framework Sections
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| 💼 CIS Azure v2.1.0 → 💼 1.11 Ensure User consent for applications Is Set To Allow for Verified Publishers - Level 2 (Manual) | 1 | no data | |||
| 💼 CIS Azure v3.0.0 → 💼 2.13 Ensure 'User consent for applications' Is Set To 'Allow for Verified Publishers' (Manual) | 1 | no data | |||
| 💼 CIS Azure v4.0.0 → 💼 6.13 Ensure that 'User consent for applications' is set to 'Allow user consent for apps from verified publishers, for selected permissions' (Manual) | 1 | no data | |||
| 💼 Cloudaware Framework → 💼 User Account Management | 19 | no data |