🎉 Our Microsoft 365 Reporting & Management Tool is available in Marketplace 🚀
Microsoft Entra ID

How to Audit Application Consent Grants in Microsoft Entra ID

Are you keeping track of which apps have access to your Microsoft 365 data? Without proper oversight of Azure AD app consent grant activities, there’s a risk of privilege escalation and potential data breaches. Regularly auditing consent to Entra apps can help detect implicit security threats and prevent sensitive data exposure. Therefore, this guide will walk you through how to track app consent activities in Microsoft Entra ID.

Microsoft 365 tools

Experience Unmatched Visibility into Microsoft Entra Application Activity!

AdminDroid’s Microsoft 365 application auditing tool provides deep insights on third-party and custom app registrations at no cost. This helps you monitor all application operations and service principal changes across your tenant through one centralized tool.

Spot Unnecessary App Registrations in Microsoft Entra

Track all newly created applications in your Microsoft 365 tenant to verify any app created without proper review.

Discover OAuth2 Consent Grants Across Entra Apps

Audit OAuth2 consents granted to applications to verify that granted permission scopes align with users’ intended purpose and usage.

Monitor App Role Assignments in Entra ID

Check app role assignments to find out if consent activities have accidentally granted elevated permissions for users or service principals.

Identify App Configuration Changes in Azure AD

Use the updated applications report to track changes in Azure AD app registrations such as permissions, redirect URIs, and more to quickly spot any misconfigurations.

Trace Credential Changes on Consented Apps

Review app credential changes report on admin-consented app registrations to detect unauthorized access and potential misuse in Entra ID.

Uncover Shifts in Entra App Delegated Permissions

Analyze the delegated permission changes on apps to identify any unexpected increases in access permission that could indicate critical security risks.

Overall, AdminDroid's Azure AD management tool redefines application visibility by providing deep insights into app permissions and access activities. This allows administrators to swiftly detect unauthorized access, track permission changes, and maintain strict control over application security.

Explore a full range of reporting options

Important Tips

Remove unused Entra ID apps granted with admin consent to minimize the risk of data leaks and avoid misuse of permissions.

Minimize manual intervention in app credential updates by using Entra app management policies to automate the lifecycle management of app credentials.

Create access reviews for apps to periodically verify user access permissions and ensure only necessary ones are retained for optimal security.

Common Errors and Resolution Steps

The following are possible errors and troubleshooting hints while managing Entra ID application consent grant activities.

Error Connect-MgGraph : InteractiveBrowserCredential authentication failed: AADSTS650053: The application 'Microsoft Graph Command Line Tools' asked for scope '' that doesn't exist on the resource '00000003-0000-0000-c000-000000000000'.

This error occurs due to the specified scopes in the 'Connect-MgGraph' cmdlet are incorrect or contain spelling mistakes.

Fix To resolve this error, verify the scopes entered are valid and ensure there are no typos.

Error New-MgPolicyPermissionGrantPolicy: PermissionGrantPolicy's Id has invalid characters. Only alphanumeric, '-', and '_' characters allowed. No whitespaces are allowed.

This error occurs because the -Id parameter’s value in the New-MgPolicyPermissionGrantPolicy cmdlet contains invalid characters or spaces.

Fix To resolve this error, ensure the -Id parameter’s value should include only letters, numbers, hyphens (-), and underscores (_).
New-MgPolicyPermissionGrantPolicy -Id "My-Custom-Policy" -DisplayName "My Custom Policy" -Description "This policy was created to show an example of how to frame policy id."

Error New-MgPolicyPermissionGrantPolicyExclude: Condition set f569a0fa-ae34-4cdb-9137-6dac7c224bed in the policy contains exact same set of conditions.

This error occurs when you try to add the same 'exclude' condition set to the app consent policy more than once.

Fix To resolve this error, ensure that existing 'exclude' condition sets are not added multiple times to the app consent policy.

Error New-MgPolicyPermissionGrantPolicyInclude: Condition set f569a0fa-ae34-4cdb-9137-6dac7c224bed in the policy contains exact same set of conditions.

This error occurs when you attempt to add an identical 'include' condition set to the app consent policy that already exists.

Fix To resolve this error, avoid adding same ‘include’ condition set more than once in the app consent policy.

Kickstart Your Journey With
AdminDroid

Your Microsoft 365 Companion with Enormous Reporting Capabilities

Download Now
User Help Manuals Compliance Docs Customer Stories