如何通过REST API或PowerShell获取Azure Entra用户同意权限设置状态?
Check Azure Entra User Consent Settings via REST API
Yes, you can use the Microsoft Graph API to automate checking the tenant-wide user consent setting you’re targeting.
API Endpoint & Request
Send a GET request to this endpoint:
GET https://graph.microsoft.com/v1.0/policies/authorizationPolicy
Required Permissions
Your authenticated request needs one of these permissions:
- Delegated:
Policy.Read.AllorDirectory.Read.All - Application:
Policy.Read.AllorDirectory.Read.All
Interpret the Response
Look for the allowUserConsentForApps boolean property in the response:
false: User consent for apps accessing company data is disabled (matches your required rule)true: User consent is enabled
Example response snippet:
{ "id": "authorizationPolicy", "allowUserConsentForApps": false, "allowUserConsentForRiskyApps": false, "allowAdminConsentForApps": true, // Additional policy properties... }
Bonus: PowerShell Alternative
If you still want a PowerShell solution using Graph, here’s a quick script:
# Connect to Microsoft Graph with required permissions Connect-MgGraph -Scopes "Policy.Read.All" # Retrieve the authorization policy $authPolicy = Get-MgPolicyAuthorizationPolicy # Check the user consent setting if ($authPolicy.AllowUserConsentForApps -eq $false) { Write-Host "User consent is disabled (compliant with your rule)" } else { Write-Host "User consent is enabled (non-compliant)" }
内容的提问来源于stack exchange,提问作者Trisha
相关产品推荐
相关产品推荐

