Microsoft 365How-To & HardeningRetrospectives

How to Lock Down User Consent to Third-Party Apps in Entra ID

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2018, written in 2026 with the benefit of hindsight.

By default, Microsoft 365 users can grant third-party apps access to their data. Malicious apps use that to steal mail and files without ever needing a password. Here is how to lock down user consent in Entra ID.

Step 1: Review current settings

In the Entra admin center, go to Enterprise applications → Consent and permissions → User consent settings. Note what is allowed today.

Step 2: Choose a safer setting

Microsoft's recommended option is to allow user consent for apps from verified publishers, for selected permissions — classified as low impact, such as signing in and reading a user's basic profile. Alternatively, block user consent entirely.

Step 3: Classify low-risk permissions

Under Permission classifications, mark the specific low-risk delegated permissions you are comfortable letting users grant (for example openid, profile, email, User.Read).

Step 4: Turn on the admin consent workflow

Enable admin consent requests so users can request apps they need. Designate reviewers and set an expiry for requests. This keeps the business moving while giving you a review step.

Step 5: Clean up existing grants

Review existing enterprise applications, focusing on:

  • Apps with permissions such as Mail.Read, Mail.ReadWrite, Files.Read.All, Sites.Read.All or Directory.ReadWrite.All.
  • Apps from unverified publishers.
  • Apps not used in 90 days.

Remove what isn't needed.

Step 6: Monitor

Alert on new consent grants for high-risk permissions. Defender for Cloud Apps app governance can flag risky or unusual app behavior.

Communicate

Tell users why the prompt now says "Need admin approval" and how to request an app.

entra id user consent settingsCambridge Analytica / OAuth2018

More on this story