logo

NAA or BroCI...? Let Me Explain

ID: d9d592c8-bb9e-5e92-979f-146942ee62bb

STIX ID: report--d9d592c8-bb9e-5e92-979f-146942ee62bb

Feed Name: SpecterOps Blog

Threat Score
50/100

Date Published: 2025-10-15

Date Updated: 2026-04-30

Author: Hope Walker

...
...

This writeup documents Nested Application Authentication (NAA) / brokered client IDs (BroCI) used by Microsoft SPAs and host applications to broker tokens for nested apps, explains the brokering flows (prefetch and on-demand), BroCI token lifetimes and request parameters, highlights tooling and enumeration resources for identifying brokerable apps, and discusses OPSEC/logging considerations and limitations that affect abuse potential.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.