MS.AAD.5.3v1 - An admin consent workflow SHALL be configured for applications.

Information

Configuring an admin consent workflow reduces the risk of the previous policy by setting up a process for users to securely request access to applications necessary for business purposes. Administrators have the opportunity to review the permissions requested by new applications and approve or deny access based on a risk assessment.

Solution

1. In Microsoft Entra admin center create a new Microsoft Entra ID Group that contains admin users responsible for reviewing and adjudicating application consent requests. Group members will be notified when users request consent for new applications.

2. Then in Microsoft Entra admin center under Applications, select Enterprise Applications.

3. Under Security, select Consent and permissions. Then select Admin consent settings.

4. Under Admin consent requests > Users can request admin consent to apps they are unable to consent to select Yes.

5. Under Who can review admin consent requests, select + Add groups and select the group responsible for reviewing and adjudicating app requests (created in step one above).

6. Click Save.

See Also

https://github.com/cisagov/ScubaGear/tree/v1.5.0/

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-4, 800-53|AC-5, 800-53|AC-6, 800-53|AC-20, 800-53|CM-5, 800-53|CM-6, 800-53|CM-7, 800-53|IA-2, 800-53|IA-5, 800-53|SC-7, 800-53|SI-4, 800-53|SI-7

Plugin: microsoft_azure

Control ID: 9f15fa878f0139507b8fadcbcf93239daa36af48c30cba1cdde90f8dbd730d7e