EIDAPP-013: Admin Consent Workflow Configuration

Platform
Entra ID / M365
Category
Consent
Severity
Medium
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

The admin consent workflow provides a structured process for users to request administrator approval before applications can access organizational data. Without an admin consent workflow, users whose consent is restricted have no formal mechanism to request application access, leading to shadow IT workarounds or helpdesk bottlenecks. A properly configured workflow ensures legitimate application requests are reviewed and approved by designated administrators.

Recommended value

Admin consent workflow enabled with designated reviewers and defined SLA for review completion

Remediation

Navigate to Entra ID > Enterprise applications > Consent and permissions > Admin consent settings. Enable the admin consent workflow and designate appropriate reviewers from your security or IT administration teams. Configure notification settings to alert reviewers of pending requests and establish a service level agreement for review turnaround to prevent workflow bottlenecks.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDAPP-013
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

CISA SCuBA
MS.AAD.5.3v1
NIST SP 800-53
AC-6
CIS M365 Benchmark
5.3.1