Question 1
Q1A financial enterprise is experiencing an increase in consent phishing attacks where end users inadvertently grant OAuth 2.0 permissions to unvetted third-party multi-tenant applications. As a cloud security engineer, you must reconfigure the tenant-wide user consent settings in Microsoft Entra ID to allow users to consent only to applications from verified publishers requesting low-risk permissions, while ensuring an approval path exists for all other applications.
Which configuration should you implement in the Microsoft Entra admin center?
Show answer & explanation
Correct answer: D
Microsoft recommends configuring user consent to 'Allow user consent for apps from verified publishers, for selected permissions' to mitigate consent phishing while allowing legitimate low-risk application adoption. Pairing this setting with the admin consent request workflow ensures that when an application requires unselected permissions or is not from a verified publisher, users can submit a request directly to administrators for formal review and approval. Setting user consent to completely disabled blocks all self-service workflows without distinguishing publisher trustworthiness, whereas allowing all user consent leaves the tenant vulnerable.