CTD-000022

Microsoft Entra tenant where regular users can register applications

High
Entra ID
Persistence Privilege Escalation
v31

Signature Identity

CTD-000022
Threat ID
31
Version
IOE
Indicator Type

Threat Description

Custom-developed applications might pose a threat to your environment. A threat actor might use an application to access data in the tenant on behalf of a user. It is recommended to prevent regular users from registering their own applications and let administrators review and register applications. This ensures that the application undergoes a security review before exposing the tenant’s data to the application.

MITRE ATT&CK: Attack Tactics

Persistence Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To prevent users from registering their own applications:

  1. In the Microsoft Entra admin center, go to the User settings section under Microsoft Entra ID.
  2. Change Users can register applications to No.

Frequently Asked Questions

What does Microsoft Entra tenant where regular users can register applications mean?

In a Microsoft Entra tenant, when regular users can register their own custom-developed applications, it allows them to access data in the tenant on behalf of themselves without administrative review. This setting enables user-assigned application permissions.

This setting is rated high severity because it increases the risk of privilege escalation and persistence, allowing attackers to expand their reach within the environment. An attacker can use a custom-developed application to access data in the tenant on behalf of a user without administrative oversight.

An attacker can exploit this setting by developing and registering a malicious application, which is then granted permissions to access data in the tenant on behalf of a user. This allows the threat actor to expand their reach within the environment and potentially gain persistence.

Cayosoft Guardian continuously monitors the settings in your Microsoft Entra environment, detecting when this setting is enabled. When found, Guardian flags it as a security issue so administrators are aware of the potential risk.

Cayosoft Guardian alerts administrators to disable this setting in the Microsoft Entra admin center, ensuring only approved and reviewed applications are allowed to access data in the tenant. This reduces the potential for privilege escalation and persistence.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Infrastructure Tenant-wide
Attack Tactics
Persistence Privilege Escalation
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical