| Recommendation | Microsoft recommends to allow to user consent for apps from verified publisher for selected permissions. CISA SCuBA 2.7 defines that all Non-Admin Users SHALL Be Prevented From Providing Consent To Third-Party Applications. |
| Configuration | policies/authorizationPolicy |
| Setting | permissionGrantPolicyIdsAssignedToDefaultUserRole -clike 'ManagePermissionGrantsForSelf*' |
| Recommended Value | 'ManagePermissionGrantsForSelf.microsoft-user-default-low' |
| Default Value | ManagePermissionGrantsForSelf.microsoft-user-default-legacy |
| Graph API Docs | authorizationPolicy resource type - Microsoft Graph v1.0 - Microsoft Learn |
| Graph Explorer | Open in Graph Explorer |