After SolarWinds (Dec 2020): Attackers Abuse Azure AD Application Credentials
Retrospective: this article looks back at events from December 2020, written in 2026 with the benefit of hindsight.
After SolarWinds was discovered in December 2020, Microsoft and incident responders described a key technique the attackers used in Microsoft 365: abusing application and service principal credentials to read email.
How it worked
In Entra ID, applications have an app registration and a service principal (enterprise application) in each tenant where they are used. Applications with application permissions — such as Mail.Read or full_access_as_app — can access data across the tenant without a signed-in user.
Attackers with sufficient privileges:
- Added new credentials (client secrets or certificates) to existing applications that already had high-privilege permissions.
- Created new applications and granted them permissions.
- Used those credentials to call Microsoft Graph or Exchange Web Services and read mail across many mailboxes.
Because the access came from an application rather than a user, it bypassed MFA and many sign-in based detections.
Why it mattered
Organizations were used to monitoring users. Applications — non-human identities — often had broad permissions, multiple credentials, unclear owners and little monitoring. They became an ideal place to hide.
Lessons in hindsight
- Inventory applications with high-privilege permissions.
- Limit who can add credentials to applications (Application Administrator and Cloud Application Administrator roles are powerful).
- Prefer certificates and managed identities over client secrets, and set short lifetimes.
- Scope mail access with application access policies or RBAC for Applications in Exchange Online.
- Monitor credential additions and service principal sign-ins.
The same pattern reappeared in Microsoft's own 2024 breach by Midnight Blizzard. Workload identity security became its own discipline.