CTD-000169

Unauthorized certificate addition to Entra ID Enterprise Application

High
Entra ID
Credential Access Defense Evasion
v11

Signature Identity

CTD-000169
Threat ID
11
Version
IOC-IOE
Indicator Type

Threat Description

The addition of a certificate to an Entra ID Enterprise Application can allow an attacker to authenticate without MFA and gain persistent access. If a threat actor compromises an account with App Admin or Owner privileges, they can add credentials to an application and use it to generate OAuth tokens for persistent access.

This method is commonly exploited in OAuth abuse attacks, where attackers use newly added credentials to impersonate users, escalate privileges, or maintain unauthorized access even after an account password reset.

By monitoring this activity, organizations can detect unauthorized persistence mechanisms and prevent potential MFA bypass attacks.

MITRE ATT&CK: Attack Tactics

Credential Access Defense Evasion

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

  1. Sign in to Microsoft Entra ID Admin Center.
  2. Navigate to Microsoft Entra ID > App registrations.
  3. In the All Applications section, search for the affected application by its name or object ID.
  4. Click the Application to open its settings.
  5. Navigate to Certificates & Secrets under the Manage section.
  6. Click the Delete icon and confirm the removal.

Frequently Asked Questions

What does Unauthorized certificate addition to Entra ID Enterprise Application mean?

This occurs when a certificate is added to an application without proper authorization, typically by an attacker who has compromised an account with App Admin or Owner privileges. The attacker can then add credentials and generate OAuth tokens for unauthorized access.

It enables attackers to bypass MFA by using compromised credentials, allowing them to authenticate without proper authorization. This leads to persistent access and potential privilege escalation due to the attacker's ability to maintain unauthorized access even after an account password reset.

Attackers use an unauthorized certificate to authenticate with Entra ID Enterprise Applications without MFA, gaining access to sensitive resources. This allows them to maintain unauthorized access even after an account password reset.

Cayosoft Guardian continuously monitors certificates added to Entra ID Enterprise Applications, detecting and flagging unauthorized additions as security issues. This enables administrators to take prompt action to remove the compromised credentials.

Cayosoft Guardian alerts administrators when an unauthorized certificate is detected, allowing them to promptly remove it from the affected application. This prevents attackers from using the compromised credentials to bypass MFA and gain persistent access.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Infrastructure
Attack Tactics
Credential Access Defense Evasion
Defend Tactics
Application Configuration Hardening
Indicator Types
IOC IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical