Information
Allow users to provide consent for selected permissions when a request is coming from a verified publisher.
If Microsoft Entra ID is running as an identity provider for third-party applications, permissions and consent should be limited to administrators or pre-approved. Malicious applications may attempt to exfiltrate data or abuse privileged user accounts.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
Remediate from Azure Portal
- From Azure Home select the Portal Menu
- Select Microsoft Entra ID
- Under Manage select Enterprise applications
- Under Security, select Consent and permissions`
- Under Manage select User consent settings
- Under User consent for applications select Allow user consent for apps from verified publishers, for selected permissions
- Click Save
Impact:
Enforcing this setting may create additional requests that administrators need to review.