APP-04: Enable Admin Consent Workflow
Frequently asked questions about implementing and managing the APP-04 security control in Microsoft 365 and Entra ID.
QWhat is APP-04 (Enable Admin Consent Workflow)?▼
APP-04 is a security control that without admin consent workflow, any user can grant an oauth app access to their data. attackers use illicit consent grant attacks to trick users into granting malicious apps access. admin approval stops this attack vector. It requires that admin consent workflow is enabled and users cannot consent to applications themselves, consent requests are routed to designated approvers.
QWhy is Enable Admin Consent Workflow important for Microsoft 365 security?▼
Without admin consent workflow, any user can grant an OAuth app access to their data. Attackers use illicit consent grant attacks to trick users into granting malicious apps access. Admin approval stops this attack vector.
QHow do I implement APP-04 in my tenant?▼
TrueConfig provides one-click remediation for APP-04. Configures admin consent workflow settings
QWhat license do I need for APP-04?▼
This control can be implemented with any Microsoft 365 subscription, including free Azure AD.
QWhich security baseline includes APP-04?▼
APP-04 is included in the Enhanced Security baseline (Level 2). This level adds stricter controls for security-conscious organizations.
5
Questions
1
Related Controls
—
Categorized
Related Resources
Still have questions?
Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.
Start Free Trial