Azure_IAM_9

Ensure that Users can consent to apps accessing company data on their behalf is set to No

Description

Require administrators to provide consent for the apps before use.

Remediation

Perform the following in the Azure Console:

  1. Go to Azure Active Directory
  2. Go to Users and group
  3. Go to User settings
  4. Set Users can consent to apps accessing company data on their behalf to No

References:

  1. https://blogs.msdn.microsoft.com/exchangedev/2014/06/05/managing-user-consent-for-applications-using-office-365-apis/
  2. https://nicksnettravels.builttoroam.com/post/2017/01/24/Admin-Consent-for-Permissions-in-Azure-Active-Directory.aspx

Service

IAM

Severity

High

Compliance

Mapping

We are now live on AWS Marketplace.
The integrated view of your cloud infrastructure is now easier than ever!