EIDAUTH-016: ROPC (Resource Owner Password Credentials) Flow Enabled

Plataforma
Entra ID / M365
Categoría
Entra ID Authentication Methods & MFA
Severidad
High
Pilar de Zero Trust
Identity (peso 3)
Fixtures de referencia
3
Cobertura de ramas
Observada: los fixtures prueban los veredictos que ejercitan
Procedencia
baseline

Qué comprueba

The Resource Owner Password Credentials (ROPC) authentication flow sends username and password directly to the token endpoint, completely bypassing multi-factor authentication and Conditional Access policies. Applications using ROPC grant type expose credentials in a way that cannot be protected by modern security controls and represent a significant security gap. ROPC should be disabled for all applications unless there is an absolute technical requirement with compensating controls.

Valor recomendado

ROPC flow disabled for all application registrations, no applications using password grant type

Remediación

Review application registrations in Entra ID > Applications > App registrations for any apps configured to allow public client flows. Disable the 'Allow public client flows' setting for applications that do not require ROPC. Migrate applications using ROPC to supported interactive flows such as authorization code with PKCE or device code flow.

Veredictos probados con fixtures

Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.

Escenarios de veredicto de EIDAUTH-016
EscenarioVeredicto esperado
cleanPASS
known-badWARN
no-dataNot Assessed

Mapeos a marcos de referencia

NIST SP 800-53
IA-2, IA-5
MITRE ATT&CK
T1078