Multi-tenant applications and partner integrations create trust chains that attackers can abuse for cross-tenant lateral movement.
Preface
Third-party SaaS and vendor apps introduce external dependencies into Entra tenants. A compromised partner registration can become a conduit into your directory.
Problem
Attackers compromise a service provider tenant, register a malicious multi-tenant app, and solicit consent downstream. After consent, they inherit permissions in the target tenant without defeating that tenant's direct authentication defenses.
Solution
Align with NIST SP 800-53 AC-3 and CIS Control 16:
- Hardened Cross-Tenant Access Policies: Restrict which external orgs can collaborate or register apps.
- Mandate inbound trust settings: Require your MFA and device compliance for incoming external users and workloads.
- Continuous consent audits: Review and revoke over-privileged third-party integrations.
PowerShell: List Third-Party Enterprise Apps
Connect-MgGraph -Scopes "Application.Read.All"
Get-MgServicePrincipal -All |
Where-Object { $_.AppOwnerTenantId -ne "your-tenant-id" } |
Select-Object DisplayName, AppId, AppOwnerTenantId | Format-Table