rules/findings/entra/app_registration/eid-application-with-client-secrets.json
|
{
"provider": "EntraID", "serviceType": "App Registrations", "serviceName": "Microsoft Entra ID", "displayName": "Ensure client secrets are removed from applications", "description": "Client secrets, also known as password credentials, are text-based secrets that applications use to authenticate to Microsoft Entra ID when acquiring access tokens. Unlike certificate-based credentials or managed identities which leverage cryptographic keys, client secrets are simple strings that can be easily copied, shared, and exposed.", "rationale": "The use of client secrets introduces significant security vulnerabilities across the application lifecycle. These secrets are frequently stored in configuration files (such as appsettings.json, web.config, or environment variable files), hardcoded directly into application source code or deployment scripts, embedded in CI/CD pipeline configurations, or stored in wikis and documentation for developer reference. Each of these storage methods creates opportunities for credential exposure through source code repository commits, configuration file leaks, developer workstation compromises, or inadvertent sharing via collaboration platforms. Once a client secret is exposed through any of these vectors, an attacker can impersonate the application and access any resources or data that the application's service principal has been granted permissions to access.", "impact": "For applications that must temporarily retain client secrets during migration, enforce strict secret management practices including storage in Azure Key Vault, implementation of automatic rotation mechanisms, restriction of secret access to only necessary personnel and services, and comprehensive audit logging of all secret retrieval operations. Establish a mandatory migration timeline with quarterly milestones requiring progressive reduction in client secret usage, and implement automated alerts for applications approaching secret expiration dates to prevent production incidents.", "remediation": { "text": " ###### To remediate using the UI: 1. Navigate to Microsoft Entra admin centre https://entra.microsoft.com/. 2. Click to expand Identity, select Applications, then select App registrations. 3. Select All applications from the dropdown. 4. For each application, select Certificates & secrets to view credential types. 5. Document applications that have entries under the Client secrets tab. 6. Prioritise applications with long-lived secrets (expiration > 90 days) or privileged permissions for immediate migration. ", "code": { "powerShell": null, "iac": null, "terraform": null, "other": null } }, "recommendation": null, "references": [ "https://learn.microsoft.com/en-us/entra/workload-id/workload-identities-overview", "https://learn.microsoft.com/en-us/entra/identity-platform/security-best-practices-for-app-registration", "https://learn.microsoft.com/en-us/azure/security/develop/secure-design", "https://cwe.mitre.org/data/definitions/798.html", "https://owasp.org/Top10/2021/A07_2021-Identification_and_Authentication_Failures/index.html" ], "compliance": [ { "name": "Monkey365 Entra", "version": "0.0.1", "reference": "5.3.1", "profile": [ ] } ], "level": "medium", "tags": [ ], "rule": { "path": "aad_app_registrations", "subPath": null, "selectCondition": { }, "query": [ { "filter": [ { "conditions": [ [ "passwordCredentials.Count", "gt", "0" ] ] } ] } ], "shouldExist": null, "returnObject": null, "removeIfNotExists": null }, "output": { "html": { "data": { "properties": { "id": "Id", "appId": "Application Id", "displayName": "Application Name" }, "expandObject": null }, "table": "default", "decorate": [ ], "emphasis": [ ], "actions": { "objectData": { "properties": [ "*" ], "expandObject": null, "limit": null }, "showGoToButton": false, "showModalButton": false, "directLink": null } }, "text": { "data": { "properties": { "id": "Id", "appId": "Application Id", "displayName": "Application Name" }, "expandObject": null }, "status": { "keyName": [ "displayName" ], "message": "Ensure client secrets are removed from {displayName}", "defaultMessage": "Ensure client secrets are removed from applications" }, "properties": { "resourceName": "displayName", "resourceId": "id", "resourceType": "EntraApplication" }, "onlyStatus": false } }, "idSuffix": "aad_applications_with_client_secret_present", "notes": [ ], "categories": [ ], "immutable_properties": [ "id" ], "id": "entraid_1174" } |