Cloud-Architekt / AzureAD-Attack-Defense

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.
2k stars 295 forks source link

Update isUsableOnce value for TemporaryAccessPass #45

Closed RobinDadswell closed 2 months ago

RobinDadswell commented 2 months ago

Currently the isUsableOnce value for TAP is setting them to disabled, this should be enabled in order to ensure they are only used one time. Screenshots below to show the graph value in my tenant and the configuration for TAP in the Entra portal.

image

image