EIDAPP-014: Application Impersonation Role Holders
- Plataforma
- Entra ID / M365
- Categoría
- Consent
- Severidad
- Critical
- Pilar de Zero Trust
- Applications & Workloads (peso 2)
- Fixtures de referencia
- 3
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
The ApplicationImpersonation role in Exchange Online grants the ability to impersonate any mailbox in the organization, allowing full read and write access to all email without the mailbox owner's knowledge. This role is frequently abused in business email compromise and data exfiltration attacks because a single compromised account with this role can access the entire organization's email. Assignments should be extremely limited, time-bound, and continuously monitored.
Valor recomendado
No permanent ApplicationImpersonation role assignments. Any required assignments must be scoped to specific mailboxes and time-limited
Remediación
Review Exchange Online role assignments to identify all principals holding the ApplicationImpersonation role using Get-ManagementRoleAssignment in Exchange Online PowerShell. Remove all unnecessary assignments immediately and replace broad impersonation grants with scoped assignments restricted to specific mailboxes where required. Implement monitoring alerts for any new ApplicationImpersonation role assignments and conduct monthly reviews of existing assignments.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| no-data | Not Assessed |
Mapeos a marcos de referencia
- NIST SP 800-53
- AC-6(5)
- MITRE ATT&CK
- T1098.002