Description:

Verifies if users can consent to application integrations in M365.

Why:

Prevent OAuth phishing by limiting application consent to administrators

Status detail shown in Augmentt: You have N connected apps. Users {action} consent for applications.

This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: General

Microsoft Licensing: Works with Basic licensing

Secure Score Impact: YES — Microsoft Secure Score control IntegratedApps.

Remediation in Augmentt: Configure directly in Augmentt (Configure tab)

Compliance Frameworks:

  • CISA SCuBA — MS.AAD.5.2

  • NIST CSF 2.0 — ID.RA-09, PR.IR-01

  • CIS Microsoft 365 Benchmark v6 (Level 2) — 5.1.5.1

  • CIS Microsoft 365 Benchmark v7 (Level 2) — 5.1.5.1

  • HIPAA Security Rule — 164.308(a)(4)(ii)(B)

  • CMMC Level 1 — AC.L1-b.1.ii

  • CMMC Level 2 — AC.L2-3.1.2, CM.L2-3.4.9

Microsoft documentation:


_KB status: already published as "Connected Apps & User Consent" — update the existing step in place._

_Source: Augmentt native check. Check ID connectedappsadminconsent (module 18)._

Sourced for this page:

  • Secure Score — Microsoft Secure Score control read by Augmentt from Microsoft Graph


Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft Entra ID · General · M365 Basic · Secure Score · NIST CSF 2.0 · HIPAA · CISA SCuBA · CIS M365 v6 L2 · CIS M365 v7 L2 · CMMC Level 1 · CMMC Level 2