Add Application
Add Application
Event
Creates the application object that describes an app’s identity configuration. Its object ID differs from its application (client) ID. A service principal is the tenant-local identity; portal registration can create both, while API workflows can create them separately. Registration alone does not establish a usable credential, consent grant, or successful authentication.
Security Context
An unauthorized registration can prepare persistent cloud identity access (contextual T1136.003). Normal software onboarding produces the same event. Do not call a registration an established backdoor without evidence of how the app authenticates and what it can access.
Log Source
Microsoft Entra directory audit logs with activityDisplayName: Add application and category: ApplicationManagement. Check result/resultReason and correlate stable object IDs. The sample uses Microsoft Graph directoryAudit-style JSON; Azure Monitor AuditLogs exports use different field names and casing.
Key Fields
| Field | Investigation value |
|---|---|
targetResources[].id, modifiedProperties | Application object and recorded changes; resolve AppId separately. |
initiatedBy | User or application initiating registration; a display name is not a permission record. |
What to Investigate
- Confirm the recorded outcome and match the initiating identity, target, and timing to an approved change.
- Verify the app owner, registration approval, sign-in audience, and redirect URI configuration.
- Correlate Add service principal, credential changes, and consent/role grants by stable identifiers.
- Review subsequent sign-ins and resource activity; neither a client ID nor a requested permission proves access.
Sample Event
Synthetic scenario. The sample records a single-tenant application registration. The application object ID and client ID are intentionally distinct; no compromise or credential creation is established.
Exact field presence, target ordering, modified-property names, and payload serialization remain unverified against captured logs. Treat these examples as illustrations, not guaranteed schemas or complete change histories.
{ "id": "Directory_90000000-0000-4000-8000-001010011011_4C2E9_77298311", "category": "ApplicationManagement", "correlationId": "90000000-0000-4000-8000-001010011011", "result": "success", "resultReason": "", "activityDisplayName": "Add application", "activityDateTime": "2026-04-15T15:42:09.5162088Z", "loggedByService": "Core Directory", "operationType": "Add", "initiatedBy": { "app": null, "user": { "id": "30000000-0000-4000-8000-001010011010", "displayName": "Draco Malfoy", "userPrincipalName": "draco@fantasticlogs.cloud", "ipAddress": "203.0.113.66" } }, "targetResources": [ { "id": "40000000-0000-4000-8000-001010011010", "displayName": "BoggartImpersonator", "type": "Application", "userPrincipalName": null, "groupType": null, "modifiedProperties": [ { "displayName": "AppAddress", "oldValue": "[]", "newValue": "[{\"AddressType\":0,\"Address\":\"https://login.microsoftonline.com/common/oauth2/nativeclient\"}]" }, { "displayName": "AppId", "oldValue": "[]", "newValue": "[\"40000000-0000-4000-8000-001010011012\"]" }, { "displayName": "DisplayName", "oldValue": "[]", "newValue": "[\"BoggartImpersonator\"]" }, { "displayName": "AvailableToOtherTenants", "oldValue": "[]", "newValue": "[false]" }, { "displayName": "SignInAudience", "oldValue": "[]", "newValue": "[\"AzureADMyOrg\"]" }, { "displayName": "Included Updated Properties", "oldValue": null, "newValue": "\"AppAddress, AppId, DisplayName, AvailableToOtherTenants, SignInAudience\"" } ] } ], "additionalDetails": [ { "key": "User-Agent", "value": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)" } ]}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1136.003 — Cloud Account — Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary credentialed access that does not require persistent remote access tools to be deployed on the system.