Description:
Verifies that only admins are allowed to register applications.
Why:
Application access for the tenant presents a heightened security risk compared to interactive user access because applications are typically not subject to critical security protections, such as MFA policies. Reduce risk of unauthorized users installing malicious applications into the tenant by ensuring that only specific privileged users can register applications.
Configured: Only admins are allowed to register applications.
Not Configured: Unprivileged users are allowed to register applications.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Identity
Microsoft Licensing: Works with Basic licensing
Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.
Remediation in Augmentt: Configure directly in Augmentt (Configure tab); Guided remediation steps (Instructions tab)
Compliance Frameworks:
CISA SCuBA — MS.AAD.5.1
CIS Microsoft 365 Benchmark v6 (Level 2) — 5.1.2.2
CIS Microsoft 365 Benchmark v7 (Level 1) — 5.1.2.2
Microsoft documentation:
_KB status: new — this check is not yet documented in the knowledge base._
_Source: Sourced from the open-source Maester project and extended by Augmentt with multi-tenant support, compliance mapping and in-product remediation. Check ID CISA.MS.AAD.5.1 (module 1034)._
Sourced for this page:
Category — Maester test catalog (maester.dev/docs/tests) — test is graded against the "Entra ID Free" tier, so it evaluates a Microsoft Entra ID setting
Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.
Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft Entra ID · M365 Basic · CIS M365 v6 L2 · CIS M365 v7 L1 · CISA SCuBA
