How to Find Forgotten Test Tenants and Over-Privileged OAuth Apps
Retrospective: this article looks back at events from January 2024, written in 2026 with the benefit of hindsight.
Midnight Blizzard got into Microsoft through a forgotten test tenant and a legacy OAuth app with production access. Here is how to find similar risks in your environment.
Part 1: Find forgotten tenants and accounts
- Tenants: ask IT, development and business units for any additional Microsoft 365 or Entra tenants (test, trial, acquisitions, projects). Check billing records and partner portals. Many organizations discover tenants created years ago for pilots.
- Cross-tenant relationships: review cross-tenant access settings and multitenant applications that link tenants.
- Accounts: in each tenant, find accounts without MFA, with no recent sign-ins, or with privileged roles.
Decommission unneeded tenants, or bring them under the same Conditional Access and monitoring as production.
Part 2: Find over-privileged OAuth apps
- List applications with high-impact application permissions:
full_access_as_app,Mail.ReadWrite,Files.ReadWrite.All,Directory.ReadWrite.All,AppRoleAssignment.ReadWrite.All,RoleManagement.ReadWrite.Directory. - Identify multitenant apps registered in other tenants (including your own test tenants) that hold permissions in production.
- Check owners, last sign-in (service principal sign-in logs) and credentials.
Defender for Cloud Apps app governance and Microsoft's Zero Trust Assessment help produce this view.
Part 3: Reduce privileges
- Remove unused apps.
- Replace
full_access_as_appwith scoped access using RBAC for Applications in Exchange Online. - Restrict who can grant admin consent and assign app roles.
Part 4: Monitor
Alert on new app role assignments with high privileges, new service principals in production created by apps from other tenants, and consent grants.
Verify
Repeat quarterly; track counts of high-privilege apps and unmanaged tenants.
- Midnight Blizzard Breaches Microsoft (Jan 2024): A Legacy Test Tenant and an OAuth App Incident Teardowns
- Detecting OAuth App Abuse: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: The Test Environment Nobody Remembered CIO Briefings