CTD-000024

Microsoft Entra tenant with unsecure app consent policy configuration

Medium
Entra ID
Lateral Movement Persistence
v28

Signature Identity

CTD-000024
Threat ID
28
Version
IOE
Indicator Type

Threat Description

A current tenant policy allows all users to consent to any permission that doesn’t require admin consent, for any application. With such a policy enabled, threat actors might receive unwarranted access to users’ data via so-called consent phishing. Threat actors trick users into granting a malicious app access to sensitive data or other resources. Instead of trying to steal the user’s password, a threat actor is seeking permission for an attacker-controlled app to access valuable data.

MITRE ATT&CK: Attack Tactics

Lateral Movement Persistence

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To configure user consent settings through the Microsoft Entra admin center:

  1. Sign in to the Microsoft Entra admin center as a Global Administrator.
  2. Select Identity > Applications > Enterprise applications > Consent and permissions > User consent settings.
  3. Under User consent for applications, select which consent setting you want to configure for all users.
  4. Select Save to save your settings. 

Frequently Asked Questions

What does Microsoft Entra tenant with unsecure app consent policy configuration mean?

Microsoft Entra tenant with unsecure app consent policy configuration means a current tenant policy allows all users to grant any permission that doesn't require admin consent, for any application. This setting enables attackers to exploit consent phishing by tricking users into granting malicious apps access to sensitive data or other resources.

This issue is rated medium severity because it allows attackers to indirectly gain unwarranted access to users' data via consent phishing, which can lead to unauthorized data exposure and places this issue in the middle of the severity scale.

Attackers might exploit consent phishing by tricking users into granting malicious apps access to sensitive data or other resources, instead of trying to steal user passwords. This allows attackers to gain unauthorized access through unsecured permissions.

Cayosoft Guardian detects this issue by continuously monitoring the state of user consent settings across your Entra ID tenant and flags it as a security issue so administrators are aware that users can grant access without admin consent.

Cayosoft Guardian helps reduce this risk by alerting administrators to configure user consent settings through the Microsoft Entra admin center, ensuring that users can only grant access to apps after explicit admin approval and limiting opportunities for attackers to exploit consent phishing.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection Tenant-wide
Attack Tactics
Lateral Movement Persistence
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical