EIDAPP-012: User Consent Settings Policy
- Platform
- Entra ID / M365
- Category
- Consent
- Severity
- High
- Zero Trust pillar
- Applications & Workloads (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
The user consent settings policy controls whether users can grant applications access to organizational data without administrator approval. Permissive consent settings allow users to authorize applications independently, which attackers exploit through illicit consent grant phishing campaigns to gain persistent access. Restricting user consent to verified publishers or disabling it entirely forces all consent through an admin approval workflow.
Recommended value
User consent disabled or restricted to apps from verified publishers with low-risk permissions only
Remediation
Navigate to Entra ID > Enterprise applications > Consent and permissions > User consent settings. Set user consent to 'Do not allow user consent' or 'Allow user consent for apps from verified publishers, for selected permissions only' with only low-risk permissions selected. Enable the admin consent workflow to provide a structured process for users to request access to applications that require admin approval.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| no-data | Not Assessed |
Framework mappings
- CISA SCuBA
- MS.AAD.5.2v1
- NIST SP 800-53
- AC-6
- CIS M365 Benchmark
- 5.3.1