Why it’s important to to disable user application consent in Microsoft 365

In a cloud-first world, Microsoft 365 provides incredible flexibility and productivity gains, but also opens new doors for potential security risks. One of the most overlooked yet critical aspects of Microsoft 365 security is user application consent. Allowing users to consent to applications on behalf of your organization can quickly become a serious vulnerability.

In this article, we’ll explore what user consent is, why it should be restricted, and how disabling it helps harden your Microsoft 365 environment against common attack vectors.


1 – What Is User Application Consent ?

User application consent is a feature in Microsoft Entra ID (formerly Azure AD) that allows end users to grant permissions to third-party apps to access organizational data such as email, calendars, contacts, or files stored in OneDrive and SharePoint.

While convenient, this setting gives non-technical users the power to authorize potentially risky access to corporate data, often without fully understanding the implications.


2 – Why You Should Disable It ?

Here are the primary security reasons to disable user consent:

  • Prevents Consent Phishing Attacks : Consent phishing is a type of attack where a user is deceived into giving permissions to a seemingly legitimate but malicious application. This allows the attacker to access emails, files, and sensitive data without needing a password. By disabling user consent, only administrators can approve app requests, which greatly reduces the risk of such attacks.
  • Stops Data Leakage via Third-Party Apps : Users might unintentionally grant access to apps that export or replicate sensitive data to external environments. Even well-intentioned productivity tools can become a problem if they are poorly secured or hosted in a jurisdiction with weak data protections. Restricting app consent to admins ensures all applications go through proper vetting and risk assessment.
  • Aligns with Least Privilege Principles : Giving users blanket authority to consent to apps violates the core security principle of least privilege. By limiting who can grant app permissions, you reduce the risk of privilege escalation or unauthorized data exposure.

3 – Disable user application consent in Microsoft 365

  1. Go to Microsoft Azure then entra ID
  2. Select “Manage” the “Entreprise Applications
  • In the right hand menu, select “Consent and Permissions
Contenu de l’article
  1. Select “Do not allow user Consent
  2. Click “Save
Contenu de l’article

You can also use this direct access link to this settings from here : https://portal.azure.com/#view/Microsoft_AAD_IAM/ConsentPoliciesMenuBlade/~/UserSettings


Conclusion

Allowing end users to freely grant application consent in Microsoft 365 introduces significant security risks. Disabling this feature helps protect against consent phishing, prevents unauthorized data access, and ensures better control over your organizational environment.

As part of a zero trust strategy, controlling user consent is not optional, it’s essential.

Thanks

Aymen EL JAZIRI (Microsoft MVP)
Aymen EL JAZIRI (Microsoft MVP)

Hi, I’m Aymen El Jaziri , a passionate System Administrator and Microsoft MVP, with years of hands-on experience in managing and securing modern IT infrastructures.
This blog is where I share technical guides, automation scripts, product reviews, and real-world solutions that help IT professionals simplify their day-to-day work and stay ahead in a fast-evolving cloud ecosystem.
Whether you’re here to troubleshoot an issue, improve your automation game, or learn new best practices , welcome in my blog !
Let’s build a stronger, smarter IT community together.
Feel free to connect with me on LinkedIn for more content, discussions, or collaboration opportunities.

Thanks

Aymen

Articles: 154