Over time a tenant collects applications: pilot projects that ended, apps whose owners left, integrations granted broad permissions years ago. Each one is a potential door. An unused app with a valid secret and Mail.ReadWrite application permission is exactly what an attacker hopes to find. Regular application hygiene is therefore part of the identity administrator's job.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.