MS.AAD.5.1v1 - Only administrators SHALL be allowed to register applications.

Information

Application access for the tenant presents a heightened security risk compared to interactive user access because applications are typically not subject to critical security protections, such as MFA policies. Reduce risk of unauthorized users installing malicious applications into the tenant by ensuring that only specific privileged users can register applications.

Solution

1. In Microsoft Entra admin center, under Manage, select Users.

2. Select User settings.

3. For Users can register applications, select No.

4. Click Save.

See Also

https://github.com/cisagov/ScubaGear/tree/v1.5.0/

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-4, 800-53|AC-5, 800-53|AC-6, 800-53|AC-20, 800-53|CM-5, 800-53|CM-6, 800-53|CM-7, 800-53|IA-2, 800-53|IA-5, 800-53|SC-7, 800-53|SI-4, 800-53|SI-7

Plugin: microsoft_azure

Control ID: 9271bddd5ecf041246d0f1c4bce0c524e8f1c6d9efef959b95278a3cbf6b9958