A water-lab user consented to a random multi-tenant app that then read mail. Which tenant control should the security engineer tighten?
Select an answer to reveal the explanation.
Short Explanation
If any lab user can say yes to a stranger’s multi-tenant app, mail walks out the door. Tighten user-consent settings so only verified publishers—or only admins—can hand out those permissions.
Full Explanation
Entra ID user-consent policies and permission classifications let administrators restrict or disable end-user consent, including blocking consent to apps from unverified publishers. That is the direct control after a risky consent incident. Defender for Cloud Apps is outside this Domain 1 consent-settings skill focus for the January 2026 AZ-500 outline. Removing Graph or disabling Conditional Access does not correctly harden consent.