EIDAPP-003: App Registrations with Added Credentials

Plataforma
Entra ID / M365
Categoría
Consent
Severidad
High
Pilar de Zero Trust
Applications & Workloads (peso 2)
Fixtures de referencia
3
Cobertura de ramas
Observada: los fixtures prueban los veredictos que ejercitan
Procedencia
baseline

Qué comprueba

Application registrations with client secrets or certificates added represent potential persistence mechanisms for attackers. A compromised secret or certificate allows an attacker to authenticate as the application and exercise all of its granted permissions without user interaction. Credentials should be inventoried, rotated on schedule, and removed when no longer needed to limit the window of exposure.

Valor recomendado

All application credentials inventoried with defined rotation schedules and no credentials older than 12 months

Remediación

Review all application registrations and examine the Certificates & secrets blade for each. Document all active credentials including their expiration dates and creation timestamps. Remove expired or unused credentials immediately and establish a rotation policy requiring credentials to be renewed at least annually with automated alerts before expiration.

Veredictos probados con fixtures

Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.

Escenarios de veredicto de EIDAPP-003
EscenarioVeredicto esperado
cleanPASS
known-badWARN
no-dataNot Assessed

Mapeos a marcos de referencia

CISA SCuBA
MS.AAD.5.5v1
NIST SP 800-53
IA-5
MITRE ATT&CK
T1098.001