EIDAPP-015: OAuth2 Permission Grants Review

Plataforma
Entra ID / M365
Categoría
Consent
Severidad
High
Pilar de Zero Trust
Applications & Workloads (peso 2)
Fixtures de referencia
3
Cobertura de ramas
Observada: los fixtures prueban los veredictos que ejercitan
Procedencia
baseline

Qué comprueba

OAuth2 permission grants define the specific permissions that applications have been authorized to exercise, either as delegated permissions acting on behalf of a user or as application permissions acting independently. Accumulated permission grants across many applications can create a complex web of access that is difficult to audit and may include overly broad or unnecessary authorizations. Regular review ensures grants remain aligned with current business requirements.

Valor recomendado

All OAuth2 permission grants reviewed quarterly with stale or excessive grants revoked

Remediación

Export all OAuth2 permission grants using Microsoft Graph and categorize them by permission type (delegated vs application), resource, and scope. Identify grants for applications that are no longer active or permissions that exceed what is required for current application functionality. Revoke unnecessary grants through the Entra admin center or Microsoft Graph API and establish a quarterly review cycle for all active grants.

Veredictos probados con fixtures

Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.

Escenarios de veredicto de EIDAPP-015
EscenarioVeredicto esperado
cleanPASS
known-badWARN
throttledNot Assessed

Mapeos a marcos de referencia

NIST SP 800-53
AC-6
MITRE ATT&CK
T1098.003