CTD-000039

Microsoft Entra application registration with dangling URI

Medium
Entra ID
Credential Access
v27

Signature Identity

CTD-000039
Threat ID
27
Version
IOE
Indicator Type

Threat Description

  1. A redirect URI, or reply URL, is the location where the authorization server sends the user once the app has been successfully authorized and granted an authorization code or access token. The authorization server sends the code or token to the redirect URI, so it’s important you register the correct location as part of the app registration process.
  2. If the corresponding App Service is deleted, but redirect URI is not deleted from the Microsoft Entra app registration, a threat actor could discover the dangling URI and register the App service instance. After registering the new App Server instance, threat actor will be able to get user sessions authorization tokens.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To remove a dangling URI in the App Registration:

  1. Go to the Microsoft Entra admin center.
  2. Select Identity > Applications > App registrations.
  3. Select the app.
  4. Open the app’s Authentication section.
  5. Delete dangling URIs in the Redirect URIs section.

Learn more about management of redirect URIs.

Frequently Asked Questions

What does Microsoft Entra application registration with dangling URI mean?

Microsoft Entra application registration with a dangling URI occurs when an app's redirect URL or reply URL remains registered in the service after its corresponding App Service has been deleted.

An exposed redirect URI can be used by attackers to discover and exploit exposed authorization tokens, increasing the risk of credential exposure. This allows attackers to gain access to user sessions' authentication information.

Attackers can use a discovered dangling URI to register a new App Server instance and obtain user sessions' authorization tokens, which can be used for malicious purposes such as lateral movement or privilege escalation through OAuth token abuse. This provides attackers with the capability to access sensitive information and compromise user accounts.

Cayosoft Guardian continuously monitors app registrations in the Microsoft Entra service for exposed redirect URIs, flagging any found as security issues to alert administrators of potential exposure and provide visibility into security posture.

Cayosoft Guardian helps reduce the risk by alerting administrators to remove exposed redirect URIs from app registrations, limiting the potential for attackers to discover and exploit exposed authorization tokens and reducing credential exposure. This supports investigation and response efforts by providing a clear audit trail of security events.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Infrastructure
Attack Tactics
Credential Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical