logo

Automating the enumeration of missing reply URLs in Azure multitenant apps

ID: 2515d9cc-5dd0-578d-8618-fef5f6b78c48

STIX ID: report--2515d9cc-5dd0-578d-8618-fef5f6b78c48

Feed Name: FalconForce

Threat Score
75/100

Date Published: 2024-07-23

Date Updated: 2026-04-27

Author: Arnau Ortega

...
...

This blog post describes an automated methodology and Python tool (reply-url-brute) to enumerate unregistered reply URLs in Azure multitenant applications, determine their type (SPA, public client, web) via OAuth interaction, brute-force scopes or auto-consent to identify pre-consented permissions, and check for domain/resource takeover opportunities that can lead to user impersonation or tenant takeover; the author demonstrates the workflow, implementation details, and a real example, and notes responsible disclosure to Microsoft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.