π Microsoft Entra ID User Consent For Applications is not set to Allow From Verified Publishers π’
- Contextual name: π User Consent For Applications is not set to Allow From Verified Publishers π’
- ID:
/ce/ca/azure/microsoft-entra-id/allow-user-consent-for-applications-from-verified-publishers
- Located in: π Microsoft Entra ID
Flagsβ
- π’ Impossible policy
- π’ Policy with categories
- π’ Policy with type
Our Metadataβ
- Policy Type:
BEST_PRACTICE
- Policy Category:
SECURITY
Similar Policiesβ
- Cloud Conformity
Descriptionβ
Descriptionβ
Allow users to provide consent for selected permissions when a request is coming from a verified publisher.
Rationaleβ
If Microsoft Entra ID is running as an identity provider for third-party applications, permissions and consent should be limited to administrators or pre-approved. Malicious applications may attempt to exfiltrate data or abuse privileged user accounts.
Impactβ
Enforcing this setting may create additional requests that administrators need to review.
Auditβ
From Azure Portalβ
- From Azure Home select the Portal Menu.
- Select
Microsoft Entra ID
.- Under
Manage
, selectEnterprise applications
.- Under
Security
, selectConsent and permissions
.- Under
Manage
, selectUser consent settings
.- Under
User consent for applications
, ensureAllow user consent for apps from verified publishers, for selected permissions
is selected.From PowerShellβ
Connect-MgGraph (Get-MgPolicyAuthorizationPolicy).DefaultUserRolePermissions | Select-Object -ExpandProperty PermissionGrantPoliciesAssigned
... [see more](description.md)
Remediationβ
Remediationβ
From Azure Portalβ
- From Azure Home select the Portal Menu.
- Select
Microsoft Entra ID
.- Under
Manage
, selectEnterprise applications
.- Under
Security
, selectConsent and permissions
.- Under
Manage
, selectUser consent settings
.- Under
User consent for applications
, selectAllow user consent for apps from verified publishers, for selected permissions
.- Select
Save
.
policy.yamlβ
Linked Framework Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ CIS Azure v2.1.0 β πΌ 1.11 Ensure User consent for applications Is Set To Allow for Verified Publishers - Level 2 (Manual) | 1 | |||
πΌ CIS Azure v3.0.0 β πΌ 2.13 Ensure 'User consent for applications' Is Set To 'Allow for Verified Publishers' (Manual) | 1 | |||
πΌ Cloudaware Framework β πΌ User Account Management | 14 |