grant consent to this Azure Active Direction app in Business Central Sandbox environment

Jason Yeung 61 Reputation points
2022-08-17T21:37:34.027+00:00

Hi,

I have an Azure Active Directory app on Business Central. On this app is a "Grant Consent" link:
232191-01-grant-content.jpg

When I click on it, it responds with a "Need admin approval" message. I did some investigation and found that the fix is the following:
https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/configure-user-consent?tabs=azure-portal

I'm not a global admin, but I asked someone who is and he had concerns about security. Specifically he said that one of Microsoft's recommendations is that we keep the setting as 'do not allow user consent". He said that if we change the setting, it will decrease the Microsoft Security identity secure score.

I was wondering if there is another way to allow us to Grant Consent, but it doesn't affect our Microsoft Security identity secure score? Thanks!

Sincerely,

Jason

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,079 questions
0 comments No comments
{count} votes

Accepted answer
  1. Vasil Michev 98,196 Reputation points MVP
    2022-08-18T06:42:46.317+00:00

    Generally speaking, it's a good idea to restrict consent requests. Blocking them altogether will affect productivity though, so a good middle ground is to configure the "request admin approval" flow as detailed here: https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/configure-admin-consent-workflow

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Jason Yeung 61 Reputation points
    2022-09-01T16:14:41.233+00:00

    Thanks @Vasil Michev ,

    I talked to our networking team as well as the development team and we've set it to "request admin approval". Development wanted to automatically approve, but we explained that it would be a security risk and have set to request as a compromise.

    Jason

    0 comments No comments