Ensure 'User consent for applications' is set to 'Allow user consent for apps from verified publishers, for selected permissions'
Description
Allow users to provide consent for selected permissions when a request is coming from a verified publisher.
Rationale
If Microsoft Entra ID is running as an identity provider for third-party applications, permissions and consent should be limited to administrators or pre-approved. Malicious applications may attempt to exfiltrate data or abuse privileged user accounts.
Impact
Enforcing this setting may create additional requests that administrators need to review.
Audit Procedure
Using Azure Portal
- From Azure Home select the Portal Menu
- Select
Microsoft Entra ID - Under
Manage, selectEnterprise applications - Under
Security, selectConsent and permissions - Under
Manage, selectUser consent settings - Under
User consent for applications, ensureAllow user consent for apps from verified publishers, for selected permissionsis selected
Using PowerShell
Connect-MgGraph
(Get-MgPolicyAuthorizationPolicy).DefaultUserRolePermissions | Select-Object -ExpandProperty PermissionGrantPoliciesAssigned
The command should return either ManagePermissionGrantsForSelf.microsoft-user-default-low or a custom app consent policy id if one is in use.
Expected Result
User consent for applications should be set to Allow user consent for apps from verified publishers, for selected permissions. PowerShell should return ManagePermissionGrantsForSelf.microsoft-user-default-low.
Remediation
Using Azure Portal
- From Azure Home select the Portal Menu
- Select
Microsoft Entra ID - Under
Manage, selectEnterprise applications - Under
Security, selectConsent and permissions - Under
Manage, selectUser consent settings - Under
User consent for applications, selectAllow user consent for apps from verified publishers, for selected permissions - Click
Save
Default Value
By default, User consent for applications is set to Allow user consent for apps.
References
- https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/configure-user-consent?pivots=ms-graph#configure-user-consent-to-applications
- https://learn.microsoft.com/en-us/security/benchmark/azure/mcsb-privileged-access#pa-1-separate-and-limit-highly-privilegedadministrative-users
- https://learn.microsoft.com/en-us/security/benchmark/azure/mcsb-governance-strategy#gs-2-define-and-implement-enterprise-segmentationseparation-of-duties-strategy
- https://learn.microsoft.com/en-us/security/benchmark/azure/mcsb-governance-strategy#gs-6-define-and-implement-identity-and-privileged-access-strategy
- https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.identity.signins/get-mgpolicyauthorizationpolicy?view=graph-powershell-1.0
CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 2.3 Address Unauthorized Software | x | x | x |
| v8 | 2.5 Allowlist Authorized Software | x | x | |
| v7 | 2.6 Address unapproved software | x | x | x |
| v7 | 2.7 Utilize Application Whitelisting | x |
Profile
Level 2 | Manual