CTD-000008

Microsoft Entra app with client secrets

Medium
Entra ID
Credential Access Defense Evasion
v33

Signature Identity

CTD-000008
Threat ID
33
Version
IOE
Indicator Type

Threat Description

App registration with client secrets poses a threat. A client secret is a string value that might be used in config files or scripts, and it can be easily compromised. Once the secret is compromised, any permissions granted to the service principal can be used by a threat actor to perform actions on behalf of an application.

MITRE ATT&CK: Attack Tactics

Credential Access Defense Evasion

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To review client secrets:

  1. In the Microsoft Entra admin center, in App registrations, select your application.
  2. Select Certificates & secrets > Client secrets.
  3. Review client secrets and delete if required.

Frequently Asked Questions

What does Microsoft Entra app with client secrets mean?

An application registered in the Microsoft Entra platform uses client secrets, which are string values stored in configuration files or scripts. If compromised, these secrets can be used by an attacker to access permissions granted to the service principal.

Client secrets can be accessed by attackers, allowing them to use them to impersonate the application and perform actions on behalf of it. This enables unauthorized access and potential credential exposure due to the elevated permissions granted to the service principal.

Attackers can exploit compromised client secrets to impersonate the application, accessing permissions granted to the service principal. This may result in unauthorized access and potential credential exposure due to the elevated permissions granted to the service principal.

Cayosoft Guardian continuously monitors registered applications' configurations in the Microsoft Entra platform, flagging client secrets as security issues when detected. This provides administrators with visibility into potential credential exposure and enables them to take proactive measures.

Cayosoft Guardian alerts administrators to review and delete client secrets, limiting the potential for credential exposure and unauthorized access. This proactive approach supports ongoing security and compliance by providing visibility into potential attack paths.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Infrastructure
Attack Tactics
Credential Access Defense Evasion
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical