Skip to content

Add Application

Azure

Add Application

service: Azure - Microsoft Entra ID
tactics:
techniques:

Event

Creates the application object that describes an app’s identity configuration. Its object ID differs from its application (client) ID. A service principal is the tenant-local identity; portal registration can create both, while API workflows can create them separately. Registration alone does not establish a usable credential, consent grant, or successful authentication.

Security Context

An unauthorized registration can prepare persistent cloud identity access (contextual T1136.003). Normal software onboarding produces the same event. Do not call a registration an established backdoor without evidence of how the app authenticates and what it can access.

Log Source

Microsoft Entra directory audit logs with activityDisplayName: Add application and category: ApplicationManagement. Check result/resultReason and correlate stable object IDs. The sample uses Microsoft Graph directoryAudit-style JSON; Azure Monitor AuditLogs exports use different field names and casing.

Key Fields

FieldInvestigation value
targetResources[].id, modifiedPropertiesApplication object and recorded changes; resolve AppId separately.
initiatedByUser or application initiating registration; a display name is not a permission record.

What to Investigate

  1. Confirm the recorded outcome and match the initiating identity, target, and timing to an approved change.
  2. Verify the app owner, registration approval, sign-in audience, and redirect URI configuration.
  3. Correlate Add service principal, credential changes, and consent/role grants by stable identifiers.
  4. Review subsequent sign-ins and resource activity; neither a client ID nor a requested permission proves access.

Sample Event

Synthetic scenario. The sample records a single-tenant application registration. The application object ID and client ID are intentionally distinct; no compromise or credential creation is established.

Exact field presence, target ordering, modified-property names, and payload serialization remain unverified against captured logs. Treat these examples as illustrations, not guaranteed schemas or complete change histories.

{
"id": "Directory_90000000-0000-4000-8000-001010011011_4C2E9_77298311",
"category": "ApplicationManagement",
"correlationId": "90000000-0000-4000-8000-001010011011",
"result": "success",
"resultReason": "",
"activityDisplayName": "Add application",
"activityDateTime": "2026-04-15T15:42:09.5162088Z",
"loggedByService": "Core Directory",
"operationType": "Add",
"initiatedBy": {
"app": null,
"user": {
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"userPrincipalName": "draco@fantasticlogs.cloud",
"ipAddress": "203.0.113.66"
}
},
"targetResources": [
{
"id": "40000000-0000-4000-8000-001010011010",
"displayName": "BoggartImpersonator",
"type": "Application",
"userPrincipalName": null,
"groupType": null,
"modifiedProperties": [
{
"displayName": "AppAddress",
"oldValue": "[]",
"newValue": "[{\"AddressType\":0,\"Address\":\"https://login.microsoftonline.com/common/oauth2/nativeclient\"}]"
},
{
"displayName": "AppId",
"oldValue": "[]",
"newValue": "[\"40000000-0000-4000-8000-001010011012\"]"
},
{
"displayName": "DisplayName",
"oldValue": "[]",
"newValue": "[\"BoggartImpersonator\"]"
},
{
"displayName": "AvailableToOtherTenants",
"oldValue": "[]",
"newValue": "[false]"
},
{
"displayName": "SignInAudience",
"oldValue": "[]",
"newValue": "[\"AzureADMyOrg\"]"
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"AppAddress, AppId, DisplayName, AvailableToOtherTenants, SignInAudience\""
}
]
}
],
"additionalDetails": [
{
"key": "User-Agent",
"value": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)"
}
]
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence

Techniques:
  • T1136.003 — Cloud Account — Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary credentialed access that does not require persistent remote access tools to be deployed on the system.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.