EIDAPP-007: App Registrations with Azure IAM Role Assignments

Platform
Entra ID / M365
Category
Consent
Severity
High
Zero Trust pillar
Applications & Workloads (weight 2)
Golden fixtures
1
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Application registrations or their corresponding service principals with Azure resource-level IAM role assignments such as Contributor, Owner, or User Access Administrator can modify Azure infrastructure, deploy resources, or escalate privileges across subscriptions. These role assignments extend the application's blast radius beyond Entra ID into the Azure resource plane, enabling infrastructure compromise if application credentials are stolen.

Recommended value

No application registrations with Azure IAM role assignments above Reader unless documented with business justification and least-privilege scope

Remediation

Review Azure IAM role assignments at the management group, subscription, and resource group levels to identify any assigned to application service principals. Remove Owner and User Access Administrator assignments and replace broad Contributor roles with custom roles scoped to specific resource types and actions. Limit IAM assignments to the narrowest scope possible, preferring resource-group level over subscription-level assignments.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDAPP-007
ScenarioExpected verdict
not-collectedNot Assessed

Framework mappings

NIST SP 800-53
AC-6
CIS Azure
1.23