How to prevent users from registering applications in Microsoft Entra
Read OriginalThis article explains the security risks of allowing standard users to register applications in Microsoft Entra (formerly Azure AD). By default, any user can create an app and become its owner, gaining control over properties and creating client secrets/certificates. This can enable unauthorized access via Microsoft Graph PowerShell. The article provides a scenario illustrating how a support manager could inadvertently gain high privileges. It then guides administrators on restricting app registration permissions through Entra ID settings, using conditional access or administrative units, and recommends best practices for securing the tenant.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser