How to Restrict Third-Party App Access in Microsoft Entra ID
Question details
Administrators need to prevent users from signing into unapproved third-party applications or adding enterprise applications without prior consent.

- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Securing enterprise identity environments and managing application access.
- Observed behavior
- Administrators want to implement strict access controls and consent requirements for all non-approved cloud applications.
Ensure you have the necessary administrative privileges, such as Conditional Access Administrator or Global Administrator, in Microsoft Entra ID before modifying access policies.
Configure Conditional Access Policies and Consent Settings
Set up policies to block unauthorized cloud apps and require admin consent for enterprise applications.
Microsoft Entra ID allows administrators to govern third-party application usage by combining Conditional Access policies with user consent settings. Testing these rules with a pilot group is crucial to prevent locking users out of essential daily services.
Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator.
Navigate to Identity > Applications > Enterprise applications > Consent and permissions. Select 'Do not allow user consent' to force admin approval before any user can add a new third-party app.
Go to Protection > Conditional Access > Policies and select 'New policy'. Name the policy to reflect its purpose, such as 'Block Unapproved Third-Party Apps'.
Under 'Target resources', select 'Cloud apps', choose 'Include', and specify 'All cloud apps'. Under 'Exclude', add your organization's approved and essential applications to ensure they continue functioning.
Under 'Access controls' > 'Grant', select 'Block access'. Set the policy state to 'Report-only' for testing with a pilot group, then switch to 'On' once verified.

Manage Your IT Documentation Effectively with WPS Office
While securing your Microsoft Entra ID environment, managing IT policies and documentation shouldn't add to your overhead. WPS Office provides a lightweight, highly compatible, and free alternative to Microsoft Office for all your administrative documentation needs.
- 1. Download WPS Office: Install the free WPS Office suite on your admin workstation.
- 2. Create IT Policies: Open WPS Writer to draft your Conditional Access and app consent policies.
- 3. Export as PDF: Use the built-in PDF tool to export your policies for secure distribution to stakeholders.

Frequently Asked Questions
What happens if I block all cloud apps in Conditional Access?
If you block all cloud apps without excluding critical services (like Microsoft Azure Management), you risk locking all users and administrators out of your environment. Always use Report-only mode first.
How do I review applications that users have requested access to?
Administrators can review admin consent requests by navigating to Identity > Applications > Enterprise applications > Admin consent requests in the Microsoft Entra admin center.
Can I restrict third-party app access for specific groups only?
Yes. When creating your Conditional Access policy, you can specify exactly which user groups the policy applies to under the 'Users' assignment section, allowing for granular control.




