MS.AAD.5.4v1 - Group owners SHALL NOT be allowed to consent to applications.

Information

In M365, group owners and team owners can consent to applications accessing data in the tenant. By requiring consent requests to go through an approval workflow, risk of exposure to malicious applications is reduced.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

1. In Microsoft Entra admin center under Applications, select Enterprise Applications.

2. Under Security, select Consent and permissions. Then select User Consent Settings.

3. Under Group owner consent for apps accessing data, select Do not allow group owner consent.

4. Click Save.

See Also

https://github.com/cisagov/ScubaGear/tree/v1.5.0/

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-4, 800-53|AC-5, 800-53|AC-6, 800-53|AC-20, 800-53|CM-5, 800-53|CM-6, 800-53|CM-7, 800-53|IA-2, 800-53|IA-5, 800-53|SC-7, 800-53|SI-4, 800-53|SI-7

Plugin: microsoft_azure

Control ID: e7459a6b499afec00166a3308e984cd5578fb634b1a1f757ac8444bccd7ef31d