An attacker has compromised an Azure AD application with the 'User.Read.All' delegated permission. They seek to elevate privileges by abusing the 'onBehalfOf' flow. What is the primary requirement for this attack to succeed?
Trap 1: The application must be configured with a client secret that…
Client secrets are used for confidential client authentication in the OAuth2 flow and are unrelated to the user's personal password. The on-behalf-of flow relies on the trust relationship between the client application and the resource server, not on shared credentials between the user and the client application.
Trap 2: The resource application must explicitly trust the client…
Trust in Microsoft Entra ID is managed through service principals and scopes, not by hardcoding Application IDs into resource applications. The flow requires the client to have obtained a valid access token for the user, which is then presented to the downstream API to request an impersonation token.
Trap 3: The target API must be configured to use Managed Identities instead…
Managed Identities are a mechanism to eliminate credential management for Azure resources but do not replace the OIDC/OAuth2 flow requirements. The on-behalf-of flow is a standard delegated permission mechanism that functions independently of whether the application running the code is using a Managed Identity or a client secret.
- A
The application must be configured with a client secret that matches the user's password.
Why it fails: Client secrets are used for confidential client authentication in the OAuth2 flow and are unrelated to the user's personal password. The on-behalf-of flow relies on the trust relationship between the client application and the resource server, not on shared credentials between the user and the client application.
- B
The resource application must explicitly trust the client application's Application ID.
Why it fails: Trust in Microsoft Entra ID is managed through service principals and scopes, not by hardcoding Application IDs into resource applications. The flow requires the client to have obtained a valid access token for the user, which is then presented to the downstream API to request an impersonation token.
- C
The initial token must contain a valid 'oid' claim and have sufficient scopes for the downstream request.
The downstream service validates that the incoming token possesses the necessary user context, represented by the object ID (oid) claim. If the initial token lacks the scope or the downstream resource does not allow the client app to act on behalf of users, the token exchange will be rejected.
- D
The target API must be configured to use Managed Identities instead of Service Principals.
Why it fails: Managed Identities are a mechanism to eliminate credential management for Azure resources but do not replace the OIDC/OAuth2 flow requirements. The on-behalf-of flow is a standard delegated permission mechanism that functions independently of whether the application running the code is using a Managed Identity or a client secret.