A critical security vulnerability has emerged in Azure Active Directory (Azure AD) that exposes sensitive application credentials, giving attackers unprecedented access to cloud environments.
See also: Critical flaws in Azure and Power allow privilege escalation

This vulnerability focuses on exposing appsettings.json files containing ClientId and ClientSecret credentials , effectively handing over the keys for entire Microsoft 365 tenants to attackers .
The vulnerability was discovered during recent cybersecurity assessments, where Azure AD application credentials were discovered in publicly accessible configuration files. This exposure allows malicious users to directly authenticate against OAuth 2.0 , impersonating trusted applications and gaining unauthorized access to sensitive organizational data.
Resecurity says the attack path exploits the Client Credential Flow in OAuth 2.0, where attackers use exposed credentials to create valid access tokens. Using the ClientId and ClientSecret, malicious users can make HTTP POST to the Azure token endpoint. Once authenticated, attackers can access the Microsoft Graph API to enumerate users, groups, and directory roles.
The vulnerability becomes particularly dangerous when applications have been granted excessive permissions such as Directory.Read.All or Mail.Read, allowing extensive data collection from SharePoint, OneDrive, and Exchange Online.
The exposed appsettings.json file typically contains critical Azure AD configuration parameters, including the Instance URL (https://login.microsoftonline.com/), TenantId for directory identification, RedirectUri for handling returns, and most importantly, the ClientSecret that acts as the application authentication code. This vulnerability allows multiple attack scenarios that pose significant risks to the security of organizations.
Attackers can perform extensive reconnaissance by querying Microsoft Graph endpoints to map organizational structures, locate highly privileged accounts, and locate repositories . The ability to enumerate OAuth2PermissionGrants reveals which applications have access to which resources, providing attackers with a roadmap for further exploitation.
See also: Microsoft Patch Tuesday March 2025: Fixes 57 vulnerabilities

Even more concerning is the possibility of application impersonation, where malicious users can develop malicious applications by violating the tenant. By using the identity of the legitimate application, attackers can request additional permissions, potentially scaling from limited read access to full administrative control. This technique bypasses traditional security controls because the requests appear to come from trusted, approved applications.
The vulnerability also allows lateral movement into cloud resources. If the exposed configuration file contains additional secrets such as storage account keys or database connection strings, attackers could gain direct access to production data, modify critical business information , or create permanent backdoors into the cloud infrastructure.
Organizations face serious compliance consequences as unauthorized access to user data can lead to GDPR, HIPAA , or SOX. This Azure AD vulnerability highlights the critical importance of proper secret management in cloud environments.
Organizations should immediately review their configuration files, implement secure credential storage solutions like Azure Key Vault , and establish monitoring for suspicious authentication patterns. The consequences of exposed application credentials extend far beyond simple data breaches, potentially compromising entire cloud ecosystems and enabling sophisticated, long-term attacks that can go undetected for months.
Azure Active Directory (Azure AD) is Microsoft's cloud-based identity and access management service. It is used by organizations to control access to applications and resources, both in the cloud and on-premises. It provides strong identity verification, supporting multi-factor authentication (MFA), Single Sign-On (SSO), and self-service password management tools. It also integrates with thousands of SaaS applications such as Microsoft 365, Salesforce, and Dropbox.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Microsoft fixes Entra ID authentication issue

Azure AD makes it easy to adopt modern security policies, such as Conditional Access and Identity Protection, protecting users from phishing attacks and identity breaches. It is a key component for Zero Trust environments. It also supports integration with on-premises Active Directory through Azure AD Connect.
