Application registrations and enterprise apps can access corporate resources silently if granted high-privilege OAuth permissions.
Preface
As identity perimeters harden, adversaries target non-human application identities. Service principals using OAuth 2.0 can reach Exchange, SharePoint, and other data without MFA or interactive session controls.
Problem
Actors such as Midnight Blizzard and Mango Sandstorm compromise low-privilege or test-tenant accounts, then register or modify multi-tenant apps.
Dangerous scopes include Mail.ReadWrite and full_access_as_app.
Attackers add their own certificates for persistence so the malicious app continues after the original account is reset or deleted.
Solution
Align with CIS Control 16 and NIST SP 800-162:
- Disable standard user consent: Require an Admin Consent Workflow.
- Restrict app registrations: Stop non-admins from creating applications.
- Prefer Workload Identity Federation or Managed Identities: Eliminate long-lived secrets where possible.
PowerShell: Harden Authorization and App Policies
Connect-MgGraph -Scopes "Directory.ReadWrite.All"
$policy = Get-MgPolicyAuthorizationPolicy
$params = @{
AllowedToCreateApps = $false
BlockUserConsentForRiskyApps = $true
}
Update-MgPolicyAuthorizationPolicy -AuthorizationPolicyId $policy.Id -BodyParameter $params