๐๐ฅ๐จ๐๐ค๐ข๐ง๐ ๐ฎ๐ฌ๐๐ซ ๐๐จ๐ง๐ฌ๐๐ง๐ญ ๐ญ๐จ ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐ง๐ญ๐ซ๐ ๐๐ ๐๐ง๐ญ๐๐ซ๐ฉ๐ซ๐ข๐ฌ๐ ๐๐ฉ๐ฉ๐ฌ
Microsoft Entra ID is primarily an identity system for Microsoft applications and services. However, you can also integrate other applications and services with Microsoft Entra ID. And itโs even highly recommended, because you get single sign-on using corporate identity, you donโt have to maintain another separate user account system, you have the ability to apply conditional access policies to these external applications and services, etc.
But the problem is that by default, even a regular user can give consent to an external application to access Microsoft Entra ID and other services tied to it. This is very risky as it can lead to leakage of sensitive internal information as such applications can have arbitrary permissions that the user gives the application access to.
๐บ Watch my YouTube video bellow on how to block user consent to Enterprise Apps in Microsoft Entra ID ๐ ๐
https://youtu.be/Ht-zcZt9nzM
#cswrld #entraid #enterpriseapps #userconsent #block