Description:

Verifies that only admins are allowed to register applications.

Why:

Application access for the tenant presents a heightened security risk compared to interactive user access because applications are typically not subject to critical security protections, such as MFA policies. Reduce risk of unauthorized users installing malicious applications into the tenant by ensuring that only specific privileged users can register applications.

Configured: Only admins are allowed to register applications.

Not Configured: Unprivileged users are allowed to register applications.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: Identity

Microsoft Licensing: Works with Basic licensing

Remediation in Augmentt: Configure directly in Augmentt (Configure tab); Guided remediation steps (Instructions tab)

Compliance Frameworks:

  • CISA SCuBA — MS.AAD.5.1

  • CIS Microsoft 365 Benchmark v6 (Level 2) — 5.1.2.2

  • CIS Microsoft 365 Benchmark v7 (Level 1) — 5.1.2.2

Microsoft documentation: