SC-300 · Question #452
You have a Microsoft Entra tenant. You need to ensure that users are prevented from consenting to high-privilege permission requests for enterprise applications. The solution must ensure that the…
The correct answer is C. User consent settings. To let users consent to low-risk permissions but block others in Microsoft Entra, use User Consent Settings in the Microsoft Entra admin center to select "Allow user consent for apps from verified publishers for selected permissions," then define those low-risk permissions…
Question
You have a Microsoft Entra tenant. You need to ensure that users are prevented from consenting to high-privilege permission requests for enterprise applications. The solution must ensure that the users can consent to low- risk permission requests. What should you modify first?
Options
- AAdmin consent settings
- BPermission classifications
- CUser consent settings
- DApp registrations
How the community answered
(32 responses)- A6% (2)
- B3% (1)
- C81% (26)
- D9% (3)
Explanation
To let users consent to low-risk permissions but block others in Microsoft Entra, use User Consent Settings in the Microsoft Entra admin center to select "Allow user consent for apps from verified publishers for selected permissions," then define those low-risk permissions under Permission classifications, requiring admin approval for anything beyond that, especially high-risk or unverified app requests. This balances security by restricting risky requests (often flagged by risk-based step-up consent) while allowing productivity for trusted apps. https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/configure-user-consent
Topics
Community Discussion
No community discussion yet for this question.