CTD-000206

Microsoft Entra ID account enumeration via unknown OAuth client ID

High
Entra ID
Discovery Initial Access

Signature Identity

CTD-000206
Threat ID
Version
IOC
Indicator Type

Threat Description

Threat actors may use unknown or non-existent OAuth client IDs in Microsoft Entra ID authentication requests to perform account enumeration, validate credentials, or evade application-based detection controls.

In this technique, the authentication request specifies an OAuth client ID that does not correspond to an application registration or service principal in the target tenant. As a result, application metadata—such as the application name, owner, or expected sign-in behavior—may be unavailable. This can reduce the effectiveness of detections that rely primarily on known application identifiers, successful sign-ins, or application-specific activity.

An authentication attempt involving an unknown OAuth client ID may indicate identity reconnaissance, credential validation, or an attempt to bypass application-centric monitoring. However, unknown client IDs can also result from application misconfiguration, obsolete clients, or requests directed to the wrong tenant.

The activity should be investigated when it is accompanied by suspicious authentication error codes, repeated attempts against multiple accounts, missing application metadata, unusual source locations or IP addresses, or other indicators of credential-testing activity. The combination of these signals may provide a high-confidence indication of malicious authentication activity.

NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.

MITRE ATT&CK: Attack Tactics

Discovery Initial Access

D3FEND: Defend Tactics

Authorization Event Thresholding

Remediation

  1. Investigate the source of the authentication attempt and determine whether it originated from a trusted application or service.
  2. Review the source IP address, user agent, and related authentication attempts from the same IP address, ASN, device, or user agent.
  3. Verify whether the targeted account had any subsequent successful sign-ins.
  4. Review Conditional Access results, sign-in logs, and risk detections associated with the targeted account.
  5. Determine whether the account may have been compromised. If compromise is suspected, reset the user’s password, revoke active sessions and refresh tokens, require reauthentication, verify MFA enrollment, and review recent account activity.
  6. Review tenant-wide activity for additional authentication attempts involving unknown OAuth client IDs.

Frequently Asked Questions

What does Microsoft Entra ID account enumeration via unknown OAuth client ID mean?

This technique involves using an unauthorized or unregistered OAuth client ID in Microsoft Entra ID authentication requests, which can be used to infer the existence of a user account and potentially obtain additional information about the account.

It allows attackers to bypass application-centric monitoring by using an unknown client ID, making it more difficult for security controls to detect and respond to malicious activity. This can lead to undetected authentication attempts from unauthorized sources.

Attackers may use this technique to gather information about user accounts, such as their existence or attributes, which can be used for further attacks or credential harvesting. This information can also be used to tailor subsequent attacks to specific users.

Cayosoft Guardian continuously monitors for Microsoft Entra ID account enumeration via unknown OAuth client ID and alerts administrators when the condition is detected. This provides visibility into the exposure so security teams can review the finding and determine whether investigation or response is required. Guardian monitors Entra ID for this condition and flags it when detected.

Cayosoft Guardian helps reduce the risk of Microsoft Entra ID account enumeration via unknown OAuth client ID by alerting administrators when the condition is detected and providing visibility into the affected accounts, roles, and application permissions. This helps security teams identify exposure more quickly and respond before the issue contributes to a larger security event.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection
Attack Tactics
Discovery Initial Access
Defend Tactics
Authorization Event Thresholding
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical