- user education
- every consent should be HIGHLY SCRUTINIZED. Every one. Especially from multitenant apps.
- restrict non-admin users from consenting to 3rd party apps, even verified publishers
/1
- user education
- every consent should be HIGHLY SCRUTINIZED. Every one. Especially from multitenant apps.
- restrict non-admin users from consenting to 3rd party apps, even verified publishers
/1
- educate admins about how these attacks work, even when "Low Risk" API permissions are consented
- if you don't have an SSPM or CASB, use
@merill's script to find Oauth2 consents in your tenant (you may be surprised how many there are) github.com/AzureAD/MSId...
/2
- educate admins about how these attacks work, even when "Low Risk" API permissions are consented
- if you don't have an SSPM or CASB, use
@merill's script to find Oauth2 consents in your tenant (you may be surprised how many there are) github.com/AzureAD/MSId...
/2
For those unaware, more info here:
learn.microsoft.com/...
The MSIdentityTools module has a report for this, but it's incomplete. I made a PR, but be sure to use exported sign-in logs (online query doesn't work):
github.com/AzureAD/M...
For those unaware, more info here:
learn.microsoft.com/...
The MSIdentityTools module has a report for this, but it's incomplete. I made a PR, but be sure to use exported sign-in logs (online query doesn't work):
github.com/AzureAD/M...
bit.ly/3X0Be5Z
bit.ly/3X0Be5Z
- fixes the Get-MsIdInactiveSignInUser commandlet
bit.ly/3M1EL1l
- fixes the Get-MsIdInactiveSignInUser commandlet
bit.ly/3M1EL1l
bit.ly/40goFE5
bit.ly/40goFE5
Also: v1.1.0 removed the version pinning of Microsoft Graph PowerShell modules from 2.25.0 so you can use newer versions now. 👏 github.com/microsoft...
Also: v1.1.0 removed the version pinning of Microsoft Graph PowerShell modules from 2.25.0 so you can use newer versions now. 👏 github.com/microsoft...
Thanks @merill.net for accepting my #PullRequest 😊
bit.ly/3wNZwGD
Thanks @merill.net for accepting my #PullRequest 😊
bit.ly/3wNZwGD
https://t.co/keUPwLiMTg https://t.co/uUfy...
https://t.co/keUPwLiMTg https://t.co/uUfy...