Microsoft Defender for Cloud Apps
Vulnerabilities and exposure

Investigate OAuth application attack paths in Defender for Cloud Apps

In brief

The Attack Paths documentation now warns that disabling an OAuth application can disrupt services and remove access for dependent users and services. It also updates headings, terminology, and page metadata.

What Defender admins need to know

Review an OAuth application's usage and dependencies before disabling it to avoid disruption.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Microsoft Defender for Cloud Apps observed an increase in attackers using OAuth applications to access sensitive data in business-critical applications like Microsoft Teams, SharePoint, Outlook, and more. To support investigation and mitigation, these applications are integrated into the attack path and attack surface map views in Microsoft Security Exposure Management.

Prerequisites

To get started with OAuth application attack path features in Exposure Management, make sure you meet the following requirements.

  • Optional: To get full access to attack path data, we recommend having an E5 security license, Defender for Endpoint or Defender for Identity license.

Required roles and permissions

To access all Exposure Management experiences, you need either a Unified Role-Based-Access-Based Access Control (RBAC) role or an Entra ID role. Only one is required.

  • Exposure Management (read) (Unified RBAC)

Critical Asset Management - Service Principals

Service principals are identities that Microsoft Entra ID assigns to applications so they can authenticate and access resources on behalf of the application rather than a user. Microsoft Defender for Cloud Apps defines a set of critical privilege OAuth permissions. OAuth applications with these permissions are considered high-value assets. If a high-value OAuth application is compromised, an attacker can gain high privileges to SaaS applications. To reflect this risk, attack paths treat service principals with these permissions as target goals.

View permissions for critical assets

  1. Optional: If you determine the OAuth application should be disabled, you can disable it from the Applications page.

Decision maker user flow: Prioritize attack path using choke points

For larger organizations with numerous attack paths that can't be manually investigated, we recommend using attack path data and utilizing the Choke Points experience as a prioritization tool. This approach allows you to:

Analyze attack surface map and hunt with queries

In the Attack surface map, you can see connections from user-owned apps, OAuth apps, and service principals. This relationship dataData about connections among user-owned apps, OAuth apps, and service principals is available in:

  • ExposureGraphEdges table (shows connections)