Entra ID & IdentityIncident TeardownsRetrospectives

After SolarWinds (Dec 2020): Attackers Abuse Azure AD Application Credentials

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2020, written in 2026 with the benefit of hindsight.

After SolarWinds was discovered in December 2020, Microsoft and incident responders described a key technique the attackers used in Microsoft 365: abusing application and service principal credentials to read email.

How it worked

In Entra ID, applications have an app registration and a service principal (enterprise application) in each tenant where they are used. Applications with application permissions — such as Mail.Read or full_access_as_app — can access data across the tenant without a signed-in user.

Attackers with sufficient privileges:

  • Added new credentials (client secrets or certificates) to existing applications that already had high-privilege permissions.
  • Created new applications and granted them permissions.
  • Used those credentials to call Microsoft Graph or Exchange Web Services and read mail across many mailboxes.

Because the access came from an application rather than a user, it bypassed MFA and many sign-in based detections.

Why it mattered

Organizations were used to monitoring users. Applications — non-human identities — often had broad permissions, multiple credentials, unclear owners and little monitoring. They became an ideal place to hide.

Lessons in hindsight

  • Inventory applications with high-privilege permissions.
  • Limit who can add credentials to applications (Application Administrator and Cloud Application Administrator roles are powerful).
  • Prefer certificates and managed identities over client secrets, and set short lifetimes.
  • Scope mail access with application access policies or RBAC for Applications in Exchange Online.
  • Monitor credential additions and service principal sign-ins.

The same pattern reappeared in Microsoft's own 2024 breach by Midnight Blizzard. Workload identity security became its own discipline.

azure ad application credential abuseApp credential abuse2020

More on this story