APP-03: Internal App Registration Permissions

Frequently asked questions about implementing and managing the APP-03 security control in Microsoft 365 and Entra ID.

Q
What is APP-03 (Internal App Registration Permissions)?
A

APP-03 is a security control that internal app registrations are applications you created and control. while you own the code, misconfigured permissions can expose excessive access. regular review ensures your own apps only have necessary permissions. It requires that internal app registrations with high-privilege graph permissions are documented and reviewed quarterly and permissions like mail.readwrite.all, directory.readwrite.all, and rolemanagement.readwrite.directory are flagged, each internal app with elevated permissions has documented business justification.

Related controls:APP-03
Q
Why is Internal App Registration Permissions important for Microsoft 365 security?
A

Internal app registrations are applications you created and control. While you own the code, misconfigured permissions can expose excessive access. Regular review ensures your own apps only have necessary permissions.

Related controls:APP-03
Q
How do I implement APP-03 in my tenant?
A

APP-03 requires manual implementation. Review flagged internal applications and remove unnecessary permissions

Related controls:APP-03
Q
What license do I need for APP-03?
A

This control can be implemented with any Microsoft 365 subscription, including free Azure AD.

Related controls:APP-03
Q
Which security baseline includes APP-03?
A

APP-03 is included in the Enhanced Security baseline (Level 2). This level adds stricter controls for security-conscious organizations.

Related controls:APP-03

5

Questions

1

Related Controls

Categorized

Related Resources

Still have questions?

Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.

Start Free Trial