CTD-000092

Stale Microsoft Entra service principal

Low
Entra ID
Defense Evasion Persistence
v38

Signature Identity

CTD-000092
Threat ID
38
Version
IOE
Indicator Type

Threat Description

A compromised Enterprise Application can be used by threat actor to access data in your tenant. If there is an application without sign-ins, it might be an indication that this Service Principal is no longer used. It is recommended to disable the Service Principal to reduce attack surface.

MITRE ATT&CK: Attack Tactics

Defense Evasion Persistence

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To delete a Service Principal (Enterprise Application):
  1. Sign in to the Microsoft Entra admin center as a Global Administrator, Cloud Application Administrator, or Application Administrator.
  2. In the left menu, select Identity > Applications > Enterprise applications. The All applications pane opens and displays a list of the applications in your Microsoft Entra tenant.
  3. Search for and select the application that you want to delete.
  4. In the Manage section of the left menu, select Properties.
  5. At the top of the Properties pane, select Delete.
  6. Select Yes to confirm you want to delete the application from your Microsoft Entra tenant.

Frequently Asked Questions

What does Stale Microsoft Entra service principal mean?

A stale Microsoft Entra service principal is a service principal in your Entra ID tenant that has been inactive or compromised, potentially allowing unauthorized access to applications and data. This condition can occur when a service principal is no longer used or has been misconfigured.

While an attacker would typically need additional steps and context to exploit the vulnerability, a stale service principal can still serve as a potential entry point for more serious attacks if left unaddressed. This is because an attacker gains access to sensitive credentials and permissions associated with the service principal.

Attackers can use a stale Microsoft Entra service principal to gain unauthorized access to applications and data in the tenant, potentially leading to changes or breaches. This is typically achieved through the misuse of service principal credentials or permissions, allowing them to escalate privileges and persist within your environment.

Cayosoft Guardian continuously monitors the state of service principals across your Entra ID tenant, flagging inactive or compromised service principals as security issues so administrators can take corrective action and provide visibility into potential attack paths.

Cayosoft Guardian helps reduce the risk of stale Microsoft Entra service principals by alerting administrators to disable or delete unused service principals, thereby reducing the attack surface and limiting potential exploitation. Guardian also supports ongoing monitoring to ensure prompt issue resolution and assist response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Infrastructure
Attack Tactics
Defense Evasion Persistence
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical