6.13 Ensure that 'User consent for applications' is set to 'Allow user consent for apps from verified publishers, for selected permissions'

Information

Allow users to provide consent for selected permissions when a request is coming from a verified publisher.

If Microsoft Entra ID is running as an identity provider for third-party applications, permissions and consent should be limited to administrators or pre-approved. Malicious applications may attempt to exfiltrate data or abuse privileged user accounts.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Remediate from Azure Portal

- From Azure Home select the Portal Menu
- Select Microsoft Entra ID
- Under Manage select Enterprise applications
- Under Security, select Consent and permissions`
- Under Manage select User consent settings
- Under User consent for applications select Allow user consent for apps from verified publishers, for selected permissions
- Click Save

Impact:

Enforcing this setting may create additional requests that administrators need to review.

See Also

https://workbench.cisecurity.org/benchmarks/19304