EIDSCA-AP08: EIDSCA AP08: Default Authorization Settings - User consent policy assigned for applications

Platform
Entra ID / M365
Category
EIDSCA Baseline
Severity
High
Zero Trust pillar
Identity (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Entra ID security-configuration control (EIDSCA AP08): evaluates 'permissionGrantPolicyIdsAssignedToDefaultUserRole' on the Entra ID authorization policy against the recommended secure value.

Recommended value

clike-any ManagePermissionGrantsForSelf

Remediation

Configure the Entra ID authorization policy so 'permissionGrantPolicyIdsAssignedToDefaultUserRole' is include ManagePermissionGrantsForSelf. (Entra ID security-configuration baseline, control EIDSCA AP08.)

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDSCA-AP08
ScenarioExpected verdict
failFAIL
no-dataNot Assessed
passPASS

Framework mappings

EIDSCA
AP08