Description:
Verifies if users can consent to application integrations in M365.
Why:
Prevent OAuth phishing by limiting application consent to administrators
Status detail shown in Augmentt: You have N connected apps. Users {action} consent for applications.
This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: General
Microsoft Licensing: Works with Basic licensing
Secure Score Impact: YES — Microsoft Secure Score control IntegratedApps.
Remediation in Augmentt: Configure directly in Augmentt (Configure tab)
Compliance Frameworks:
CISA SCuBA — MS.AAD.5.2
NIST CSF 2.0 — ID.RA-09, PR.IR-01
CIS Microsoft 365 Benchmark v6 (Level 2) — 5.1.5.1
CIS Microsoft 365 Benchmark v7 (Level 2) — 5.1.5.1
HIPAA Security Rule — 164.308(a)(4)(ii)(B)
CMMC Level 1 — AC.L1-b.1.ii
CMMC Level 2 — AC.L2-3.1.2, CM.L2-3.4.9
Microsoft documentation:
