How to Lock Down User Consent to Third-Party Apps in Entra ID
Retrospective: this article looks back at events from March 2018, written in 2026 with the benefit of hindsight.
By default, Microsoft 365 users can grant third-party apps access to their data. Malicious apps use that to steal mail and files without ever needing a password. Here is how to lock down user consent in Entra ID.
Step 1: Review current settings
In the Entra admin center, go to Enterprise applications → Consent and permissions → User consent settings. Note what is allowed today.
Step 2: Choose a safer setting
Microsoft's recommended option is to allow user consent for apps from verified publishers, for selected permissions — classified as low impact, such as signing in and reading a user's basic profile. Alternatively, block user consent entirely.
Step 3: Classify low-risk permissions
Under Permission classifications, mark the specific low-risk delegated permissions you are comfortable letting users grant (for example openid, profile, email, User.Read).
Step 4: Turn on the admin consent workflow
Enable admin consent requests so users can request apps they need. Designate reviewers and set an expiry for requests. This keeps the business moving while giving you a review step.
Step 5: Clean up existing grants
Review existing enterprise applications, focusing on:
- Apps with permissions such as
Mail.Read,Mail.ReadWrite,Files.Read.All,Sites.Read.AllorDirectory.ReadWrite.All. - Apps from unverified publishers.
- Apps not used in 90 days.
Remove what isn't needed.
Step 6: Monitor
Alert on new consent grants for high-risk permissions. Defender for Cloud Apps app governance can flag risky or unusual app behavior.
Communicate
Tell users why the prompt now says "Need admin approval" and how to request an app.