cisagov / ScubaGear

Automation to assess the state of your M365 tenant against CISA's baselines
https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project
Creative Commons Zero v1.0 Universal
1.6k stars 215 forks source link

MS.AAD.5.4v1 setting discontinued by Microsoft #1139

Open ahuynhMITRE opened 4 months ago

ahuynhMITRE commented 4 months ago

🐛 Summary

What's wrong? Please be specific. MS.AAD.5.4v1 notes Group owners SHALL NOT be allowed to consent to applications. An FCEB agency during a technical exchange meeting has noted that this option is no longer supported in the admin center and thus the policy needs to be updated to reflect the change.

This includes removal of the current policy and checks and investigation into the new "Team owner consent settings"

To reproduce

Steps to reproduce the behavior:

  1. Run Scubagear and receive a "FAIL" for MS.AAD.5.4v1
  2. Return to the admin center and view the notice that "Group owener consent settings have been removed and replaced with team owner consent settings". Screenshot attached below

image image image

Expected behavior

What did you expect to happen that didn't?

PASS / FAIL test results based upon the previously set setting.