Default Authorization Settings - Risk-based step-up consent
Indicates whether user consent for risky apps is allowed. For example, consent requests for newly registered multi-tenant apps that are not publisher verified and require non-basic permissions are considered risky.
Name | allowUserConsentForRiskyApps |
Control | Default Authorization Settings |
Description | Manages authorization settings in Azure AD |
Severity | High |
How to fix
Details of configuration item
Recommendation | Configure risk-based step-up consent - Microsoft Entra ID - Microsoft Learn |
Configuration | policies/authorizationPolicy |
Setting | allowUserConsentForRiskyApps |
Recommended Value | 'false' |
Default Value | false |
Graph API Docs | authorizationPolicy resource type - Microsoft Graph v1.0 - Microsoft Learn |
Graph Explorer | Open in Graph Explorer |