logo
search
Conditional Access Problems

How to Restrict Third-Party App Access in Microsoft Entra ID

Ayan MasoodAyan Masood Sep 28, 2026 869 views

Question details

Administrators need to prevent users from signing into unapproved third-party applications or adding enterprise applications without prior consent.

How to Restrict Third-Party and Enterprise Application Access in Microsoft Entra ID
Product
Microsoft Entra ID
Device & OS
not provided
Scenario
Securing enterprise identity environments and managing application access.
Observed behavior
Administrators want to implement strict access controls and consent requirements for all non-approved cloud applications.
Before you start

Ensure you have the necessary administrative privileges, such as Conditional Access Administrator or Global Administrator, in Microsoft Entra ID before modifying access policies.

Solution 1Recommended

Configure Conditional Access Policies and Consent Settings

Set up policies to block unauthorized cloud apps and require admin consent for enterprise applications.

Microsoft Entra ID allows administrators to govern third-party application usage by combining Conditional Access policies with user consent settings. Testing these rules with a pilot group is crucial to prevent locking users out of essential daily services.

1
Access Entra ID Admin Center

Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator.

2
Configure Consent Settings

Navigate to Identity > Applications > Enterprise applications > Consent and permissions. Select 'Do not allow user consent' to force admin approval before any user can add a new third-party app.

3
Create a Conditional Access Policy

Go to Protection > Conditional Access > Policies and select 'New policy'. Name the policy to reflect its purpose, such as 'Block Unapproved Third-Party Apps'.

4
Assign Target Applications

Under 'Target resources', select 'Cloud apps', choose 'Include', and specify 'All cloud apps'. Under 'Exclude', add your organization's approved and essential applications to ensure they continue functioning.

5
Enforce Block Access

Under 'Access controls' > 'Grant', select 'Block access'. Set the policy state to 'Report-only' for testing with a pilot group, then switch to 'On' once verified.

Configure Conditional Access Policies and Consent Settings
Pilot Group Testing: Always use a pilot group and 'Report-only' mode first. Blocking all cloud apps without proper exclusions can lock administrators out of the Azure portal itself.
Free Microsoft Office alternative

Manage Your IT Documentation Effectively with WPS Office

While securing your Microsoft Entra ID environment, managing IT policies and documentation shouldn't add to your overhead. WPS Office provides a lightweight, highly compatible, and free alternative to Microsoft Office for all your administrative documentation needs.

  1. 1. Download WPS Office: Install the free WPS Office suite on your admin workstation.
  2. 2. Create IT Policies: Open WPS Writer to draft your Conditional Access and app consent policies.
  3. 3. Export as PDF: Use the built-in PDF tool to export your policies for secure distribution to stakeholders.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight design ensures fast loading times for heavy IT policy documents.Familiar user interface requires zero learning curve for seamless migration.Built-in PDF editing tools for securing and sharing access policies securely.
microsoft office alternative - wps office

Frequently Asked Questions

What happens if I block all cloud apps in Conditional Access?

If you block all cloud apps without excluding critical services (like Microsoft Azure Management), you risk locking all users and administrators out of your environment. Always use Report-only mode first.

How do I review applications that users have requested access to?

Administrators can review admin consent requests by navigating to Identity > Applications > Enterprise applications > Admin consent requests in the Microsoft Entra admin center.

Can I restrict third-party app access for specific groups only?

Yes. When creating your Conditional Access policy, you can specify exactly which user groups the policy applies to under the 'Users' assignment section, allowing for granular control.