Upgrade to Pro — share decks privately, control downloads, hide ads and more …

The App Registration That Ate the Tenant

The App Registration That Ate the Tenant

Talk presented at Global Security Bootcamp Adelaide 2026.

Avatar for Renaldi Gondosubroto

Renaldi Gondosubroto

August 30, 2026

More Decks by Renaldi Gondosubroto

Other Decks in Technology

Transcript

  1. #GSBADL2026 GLOBAL SECURITY BOOTCAMP · ADELAIDE 2026 The App Registration

    That Ate the Tenant A defensive tour of non-human identity risk in Microsoft environments Presented by Renaldi Gondosubroto Senior Software Engineer and Consultant 22 August 2026 · Microsoft Adelaide, Level 12, 147 Pirie Street
  2. SPEAKER Renaldi Gondosubroto Senior Software Engineer and Consultant ABOUT CONNECT

    @Renaldig @renaldigondosubroto @renaldig Global Security Bootcamp Adelaide 2026 · 22 August 2026 • Currently hold all 13 certifications from AWS and 22 Microsoft Azure certifications • Organizer of the Melbourne Python Meetup • International speaker at 60+ events and conferences • Author of books like AI-102 Study Guide and Instructor • Enjoy all things cloud, open-source, testing, and virtual reality globalsecurity.community
  3. CONNECT What we’ll cover The story The anatomy The demo

    The fix A normal automation app slowly becomes a tenantlevel risk. App objects, service principals, Graph, Azure roles, credentials. Inspect permissions, consent, owners, credentials, and logs. Reduce blast radius with lifecycle and secretless patterns. The mental model • Non-human identities are identities • Application permissions do not need a user in the loop • Governance drift is the real villain Global Security Bootcamp Adelaide 2026 · 22 August 2026 globalsecurity.community
  4. PART 01 How a helpful app becomes invisible privilege The

    risk is what the app accumulates after the first deployment.
  5. THE APP REGISTRATION THAT ATE THE TENANT Human-first controls leave

    a blind spot • MFA and device rules are built around people • Apps can hold broad Graph permissions with no interactive user • Long-lived secrets quietly outlive teams, projects, and owners • “It just runs” often means “nobody reviews it” Risk pattern Good intent + broad consent + stale credential + no owner = quiet blast radius. Reference concepts: Microsoft Entra workload identities and Microsoft Graph permission models. Global Security Bootcamp Adelaide 2026 · 22 August 2026 globalsecurity.community
  6. THE APP REGISTRATION THAT ATE THE TENANT The reasonable app

    that slowly grows teeth 01 02 03 04 05 Business need Small shortcut Operational fix Ownership drift Tenant blast radius Read group membership for a dashboard Add Graph permission to “finish the report” Add write permission for sync and cleanup Team changes; app stays trusted Credential leak or misuse becomes high impact The failure is rarely one bad permission. It is the missing review loop. Global Security Bootcamp Adelaide 2026 · 22 August 2026 globalsecurity.community
  7. THE APP REGISTRATION THAT ATE THE TENANT Anatomy of the

    risk App registration Service principal Credentials Access planes Template: app ID, redirect URIs, requested API permissions Tenant instance: consent grants, assignments, sign-in activity Secrets, certificates, federated identity credentials Microsoft Graph, Azure RBAC, Key Vault, downstream APIs Identity object → tenant instance → authentication method → effective access Defender question: “Where can this app go, what can it do, and who can explain why?” Source concepts: Microsoft Entra workload identities overview; Microsoft Graph permissions overview. Global Security Bootcamp Adelaide 2026 · 22 August 2026 globalsecurity.community
  8. THE APP REGISTRATION THAT ATE THE TENANT Delegated vs application

    permissions Delegated Application • Acts on behalf of a signed-in user • Bound by what that user can access • Consent risk depends on user + app + scope • Acts as the app itself • No user needs to be present at runtime • Can be tenant-wide when broad scopes are granted The danger word is usually “.All”. Microsoft describes delegated permissions as acting on behalf of a user and application permissions as app-only access. Global Security Bootcamp Adelaide 2026 · 22 August 2026 globalsecurity.community
  9. THE APP REGISTRATION THAT ATE THE TENANT The ecosystem you

    actually have to govern Global Security Bootcamp Adelaide 2026 · 22 August 2026 globalsecurity.community
  10. THE APP REGISTRATION THAT ATE THE TENANT Privilege drift is

    the quiet failure mode Access Credentials Ownership Monitoring Permissions added for urgent features Secrets created “temporarily” and never removed Original team moves on; app stays in production Sign-ins exist, but nobody hunts the pattern Audit question “Can we prove this app still needs every permission, credential and role it has today?” If the answer is “probably”, you have work to do. Global Security Bootcamp Adelaide 2026 · 22 August 2026 globalsecurity.community
  11. THE APP REGISTRATION THAT ATE THE TENANT Demo: defensive visibility

    tour We are inspecting how invisible privilege becomes visible. Find Inspect Inventory app registrations and enterprise apps Graph permissions, consent, owners and assignments Question Harden Delegated vs application permissions and business need Remove stale credentials, reduce scopes, set review loop Demo safety lens: prove risk without creating risk. Global Security Bootcamp Adelaide 2026 · 22 August 2026 globalsecurity.community
  12. THE APP REGISTRATION THAT ATE THE TENANT Global Security Bootcamp

    Adelaide 2026 · 22 August 2026 globalsecurity.community
  13. THE APP REGISTRATION THAT ATE THE TENANT What to inspect

    first Graph application permissions Directory.ReadWrite.All, Group.ReadWrite.All, Mail.Read, Files.Read.All, User.ReadWrite.All Consent details Who granted it? Was it admin consent? Is there a ticket or owner? Effective access Graph scopes are only one part. Also check Azure RBAC and app roles Global Security Bootcamp Adelaide 2026 · 22 August 2026 Look for permissions that let an app read or write across users, groups, mail, files or directory objects. globalsecurity.community
  14. THE APP REGISTRATION THAT ATE THE TENANT Credentials: the part

    attackers love and teams forget Stale secrets Old, long-lived, duplicated, or unknown origin Certificate hygiene Better than secrets, but still needs ownership and expiry review Federated identity credentials Prefer short-lived token exchange where supported Goal: no reusable secret where a workload can use a trusted identity pattern instead. Microsoft workload identity federation guidance describes secretless access for supported workloads. Global Security Bootcamp Adelaide 2026 · 22 August 2026 globalsecurity.community
  15. THE APP REGISTRATION THAT ATE THE TENANT Consent is a

    security decision Consent answers two questions: Who is asking? Publisher, owner, app purpose, tenant context What are they asking for? Delegated or app-only? Read or write? Narrow or tenantwide? Defensive controls • Limit user consent • Use admin consent workflow • Define app consent policies • Review grants routinely Microsoft Entra supports configuring user consent settings and app consent policies. Global Security Bootcamp Adelaide 2026 · 22 August 2026 globalsecurity.community
  16. THE APP REGISTRATION THAT ATE THE TENANT Reduce blast radius

    before you chase perfection Remove unused permissions Scope to the smallest resource Start with broad Graph app permissions and stale Azure role assignments Mailbox, group, site, resource group, vault, or custom app role Separate duties Add expiry and review One app for one purpose; avoid shared “automation superapps” Make permissions, credentials and owners expire unless renewed Least privilege is the habit of deleting what no longer earns its keep. Global Security Bootcamp Adelaide 2026 · 22 August 2026 globalsecurity.community
  17. THE APP REGISTRATION THAT ATE THE TENANT Kill the secret

    where you can Managed identity Best fit for Azure-hosted workloads that need Azure resource access Workload identity federation Best fit for CI/CD and external workloads that support OIDC trust Certificates Still valid, but require expiry, storage and ownership discipline Secretless removes one very common failure mode. Microsoft docs recommend workload identity federation for several service-connection and workload scenarios where supported. Global Security Bootcamp Adelaide 2026 · 22 August 2026 globalsecurity.community
  18. THE APP REGISTRATION THAT ATE THE TENANT Monitor service principals

    like privileged users Service principal sign-ins Where did the app sign in from, how often, and did the pattern change? Audit logs Who added credentials, permissions, owners or app role assignments? Alerting and hunting Watch for new high-impact permissions, new secrets, and unusual app-only activity. A dormant app that suddenly becomes active should feel as suspicious as a dormant admin account. Global Security Bootcamp Adelaide 2026 · 22 August 2026 globalsecurity.community
  19. THE APP REGISTRATION THAT ATE THE TENANT Monday checklist Inventory

    Owners Export app registrations + enterprise apps Require real owners and business purpose Permissions Credentials Flag Graph app permissions, especially broad read/write Remove stale secrets and set expiry policy Consent Roles Review admin grants and user consent settings Check Azure RBAC, app roles and Key Vault access Logs Review Enable sign-in/audit review and alert on changes Create recurring recertification with evidence Start with the apps that have broad Graph application permissions or active credentials older than your review cycle. Global Security Bootcamp Adelaide 2026 · 22 August 2026 globalsecurity.community
  20. Thank you. Leave with ideas you can take back to

    your organisation on Monday. Key takeaway: every automation app deserves an owner, a purpose, a permission boundary, and a review date. globalsecurity.community · #GSBADL2026