Restrict Third-Party OAuth App Consent in Entra ID for Microsoft 365 Security

▶ Watch the short explainer for this tip
Today's tech tip focuses on a crucial security setting: restricting user consent to third-party OAuth apps in Microsoft Entra ID. This simple change can significantly bolster your organisation's cybersecurity posture, especially for Australian small and medium businesses. Without proper controls, users can inadvertently grant permissions to malicious or risky applications, creating backdoors for data exfiltration and business email compromise (BEC) attacks. Let's lock it down.
What is Restricting User Consent for OAuth Apps?
Restricting user consent for third-party OAuth apps in Microsoft Entra ID means you control which applications users can authorise to access your organisation's data. Instead of users freely connecting apps, you establish a managed process, typically requiring administrator approval for new applications.
Why Should You Change This Setting Now?
You should change this setting to prevent unauthorised applications from gaining access to your organisation's sensitive data. By centralising app approval, you drastically reduce the risk of shadow IT and malicious apps compromising your Microsoft 365 environment. This is a fundamental step in preventing business email compromise (BEC) and protecting your data from external threats.
What Happens If You Leave This Setting Unchanged?
If you leave this setting as-is, users can connect any third-party application to your Entra ID environment without oversight. This leaves your organisation vulnerable to data breaches, as a compromised or malicious app could gain broad access to user mailboxes, files, and other sensitive information. Such breaches can lead to significant financial loss, regulatory penalties under privacy laws, and damage to your business's reputation, potentially invalidating cyber insurance claims.
How to Restrict User Consent in Entra ID
Here are the verified steps to restrict user consent to third-party OAuth apps, ensuring a more secure Microsoft 365 environment for Australian businesses: 1. Sign in to entra.microsoft.com as a Global Administrator. 2. Go to Entra ID > Enterprise applications > Security > Consent and permissions > User consent settings. 3. Select Allow user consent for apps from verified publishers, for selected permissions, and choose a low-risk permission set (or select Do not allow user consent to lock it down completely). 4. Open Admin consent settings, turn on Users can request admin consent to apps they are unable to consent to, nominate the reviewers, and Save.
How to Verify Your Changes and What to Warn Staff About
You can check your changes worked by navigating to Enterprise applications > Admin consent requests. You should see new requests appearing there instead of unapproved apps appearing unannounced. Staff will now encounter a 'needs admin approval' prompt when trying to use new applications. It's crucial to proactively inform them that these requests will come to you, and set clear expectations for the turnaround time to avoid frustration. If you'd like a deep dive into your current security, book a complimentary 15-minute chat with Neil to discuss a Microsoft 365 security audit.
Important Disclaimer for Your Security
These steps are accurate at the time of publishing, but email platform menus and defaults can change. If you're not confident, please don't change settings yourself, as incorrect modifications can disrupt email service. SecureMyEmail accepts no responsibility for loss or damage caused by changes made without our direct involvement.
Restricting user consent for OAuth apps is a fundamental security control that every Australian small and medium business using Microsoft 365 should implement. It minimises risk and ensures that only approved applications can access your organisation's data, protecting you from breaches and compliance issues.
Disclaimer: These steps are accurate at the time of publishing, but email platform menus and defaults can change. If you're not confident, please don't change settings yourself, as incorrect modifications can disrupt email service. SecureMyEmail accepts no responsibility for loss or damage caused by changes made without our direct involvement.
Frequently asked questions
- What is OAuth app consent in Microsoft 365?
- OAuth app consent is when a user or administrator grants permission for an application to access data within their Microsoft 365 environment, using the OAuth authorisation framework. This allows third-party apps to integrate with services like Exchange Online or SharePoint.
- Why is restricting app consent important for Australian small businesses?
- Restricting app consent is vital for Australian small businesses because it significantly reduces the risk of data breaches, ransomware, and business email compromise (BEC) attacks. Uncontrolled app access can expose sensitive customer and business data, leading to financial loss and reputational damage, especially under privacy regulations.
- How do I know if an app is verified by Microsoft?
- Microsoft maintains a program for verified publishers, and apps from these publishers usually display a 'verified' badge during the consent prompt. This offers an extra layer of trust, but it's still best practice to review permissions even for verified apps.
- What happens if a user tries to install an unapproved app after I change this setting?
- If a user tries to install an unapproved app after you restrict consent, they will receive a prompt stating that administrator approval is required. This request will then be routed to the nominated administrators for review and decision, preventing unmanaged app installations.
- Will restricting app consent disrupt our existing applications?
- No, changing this setting typically only affects *new* applications that users attempt to consent to. Existing, previously approved applications should continue to function without interruption. However, it's always wise to test any changes in a non-production environment first if possible.
Sources
Every reference below was link-checked when this article was published.
- 1.Manage app consent policiesMicrosoft Learn
Want to know where your own tenant stands?
The audit answers these questions with a dated report on your actual settings — a few questions to start, under a minute.


