🔒 New browser security hardening is live to help defend against AI-driven attacks. Learn more

Create Collaboration Attack Surface Report for Email and SharePoint - Entra ID App Registration

Prev Next

This document describes the steps to create a custom eSHARE Collaboration Attack Surface Report for Email and SharePoint applications in Microsoft Entra (Azure AD) portal. At a high level, the steps involved are:

REQUIREMENT

The Person performing these steps must have an administrator role assignment of Application Administrator, Cloud Application Administrator, or Global Administrator in the destination M365 tenant.

NOTE:

Depending on the size of your organization’s M365 tenant, multiple App Registrations may be required for optimal performance. The recommended number of App Registrations to create and provide to your eSHARE Customer Success Manager is 3 apps.

Application Registration

  • To register the custom App Registration for the Email Risk Report, login to Microsoft Entra console (https://entra.microsoft.com or https://entra.microsoft.us) and navigate to ‘Applications‘ > ‘App Registrations‘.

  • In ‘App Registrations‘ page, click the ‘+ New registration‘ button in top menu bar.

  • Input a recognizable unique name for the custom eShare app and select the ‘Register‘ button at bottom of the page.

In a few moments, a shell application is created and ready for further configuration.

Modify Application Manifest - Commercial Cloud

requiredResourceAccess

  • In the newly registered application page, navigate to the ‘Manage‘ > ‘Manifest‘ tab.  

  • In the applications’ manifest, look for ‘requiredResourceAccess‘.

  • Replace the above string (including the comma at the end) from line 53 to 63 with the below text.

	"requiredResourceAccess": [
		{
			"resourceAppId": "00000003-0000-0ff1-ce00-000000000000",
			"resourceAccess": [
				{
					"id": "d13f72ca-a275-4b96-b789-48ebcc4da984",
					"type": "Role"
				}
			]
		},
		{
			"resourceAppId": "c5393580-f805-4401-95e8-94b7a6ef2fc2",
			"resourceAccess": [
				{
					"id": "594c1fb6-4f81-4475-ae41-0c394909246c",
					"type": "Role"
				},
				{
					"id": "4807a72c-ad38-4250-94c9-4eabfe26cd55",
					"type": "Role"
				}
			]
		},
		{
			"resourceAppId": "00000003-0000-0000-c000-000000000000",
			"resourceAccess": [
				{
					"id": "5e1e9171-754d-478c-812c-f1755a9a4c2d",
					"type": "Role"
				},
				{
					"id": "98830695-27a2-44f7-8c18-0c3ebc9698f6",
					"type": "Role"
				},
				{
					"id": "19da66cb-0fb0-4390-b071-ebc76a349482",
					"type": "Role"
				},
				{
					"id": "810c84a8-4a9e-49e6-bf7d-12d183f40d01",
					"type": "Role"
				},
				{
					"id": "40f97065-369a-49f4-947c-6a255697ae91",
					"type": "Role"
				},
				{
					"id": "332a536c-c7ef-4017-ab91-336970924f0d",
					"type": "Role"
				},
				{
					"id": "df021288-bdef-4463-88db-98f22de89214",
					"type": "Role"
				}
			]
		}
	],
  • Click the ‘Save‘ button in top menu bar.

Modify Application Manifest - Government Cloud

requiredResourceAccess

  • In the newly registered application page, navigate to the ‘Manage’ > ‘Manifest’ tab.  

  • In the applications’ manifest, look for ‘requiredResourceAccess’.

  • Replace the above string (including the comma at the end) from line 58 to 68 with the below text.

	"requiredResourceAccess": [
		{
			"resourceAppId": "00000003-0000-0ff1-ce00-000000000000",
			"resourceAccess": [
				{
					"id": "d13f72ca-a275-4b96-b789-48ebcc4da984",
					"type": "Role"
				}
			]
		},
		{
			"resourceAppId": "c5393580-f805-4401-95e8-94b7a6ef2fc2",
			"resourceAccess": [
				{
					"id": "594c1fb6-4f81-4475-ae41-0c394909246c",
					"type": "Role"
				},
				{
					"id": "4807a72c-ad38-4250-94c9-4eabfe26cd55",
					"type": "Role"
				}
			]
		},
		{
			"resourceAppId": "00000003-0000-0000-c000-000000000000",
			"resourceAccess": [
				{
					"id": "5e1e9171-754d-478c-812c-f1755a9a4c2d",
					"type": "Role"
				},
				{
					"id": "98830695-27a2-44f7-8c18-0c3ebc9698f6",
					"type": "Role"
				},
				{
					"id": "19da66cb-0fb0-4390-b071-ebc76a349482",
					"type": "Role"
				},
				{
					"id": "810c84a8-4a9e-49e6-bf7d-12d183f40d01",
					"type": "Role"
				},
				{
					"id": "40f97065-369a-49f4-947c-6a255697ae91",
					"type": "Role"
				},
				{
					"id": "332a536c-c7ef-4017-ab91-336970924f0d",
					"type": "Role"
				},
				{
					"id": "df021288-bdef-4463-88db-98f22de89214",
					"type": "Role"
				}
			]
		}
	],
  • Click the ‘Save‘ button in top menu bar.  

REQUIREMENT:

Granting admin consent for permissions within an app registration must be performed by a Global Administrator in the destination M365 tenant. Below is a list of all the API permissions required.

Permission

Display Name

Description

Admin Consent Required

MailboxSettings.Read

Read all user mailbox settings

Allows the app to read user mailbox settings without a signed-in user. Does not include permission to send mail.

Yes

Mail.Read

Read mail in all mailboxes

Allows the app to read mail in all mailboxes without a signed-in user.

Yes

InformationProtectionPolicy.Read.All

Read all published labels and label policies

Allows the app to read published sensitivity labels and label policy settings for the entire organization or a specific user, without a signed-in user.

Yes

GroupMember.Read.All

Read all group memberships

Allows the app to read memberships and basic group properties for all groups without a signed-in user.

Yes

AuditLogsQuery.Read.All

Read audit logs data from all services

Allows the app to read and query audit logs from all services.

Yes

User.Read.All

Read all users' full profiles

Allows the app to read user profiles without a signed-in user.

Yes

Sites.Read.All (Graph API)

Read items in all site collections

Allows the app to read documents and list items in all site collections without a signed-in user.

Yes

Activity.Feed.Read

Read activity data for your organization

Allows the application to read activity data for your organization.

Yes

ActivityFeed.ReadDlp

Read DLP policy events including detected sensitive data

Allows the application to read DLP policy events, including detected sensitive data, for your organization.

Yes

Sites.Read.All (SharePoint API)

Read items in all site collections

Allows the app to read documents and list items in all site collections without a signed in user.

  • For the saved application, navigate to the ‘Manage‘ > ‘API permissions‘ tab.

  • Select ‘Grant admin consent for <tenant name>‘ in top of the API permissions table.

  • Confirm when prompted.

Upload Application Certificate

  • Option 1: Purchase a certificate from well-known certificate authority, extract the private and public portions of the certificate. Upload the public portion in Azure portal for the application and upload the private key in your eShare admin console (or provide the private key to your eShare admin).  

  • Option 2: Create a self-signed certificate by following instructions available at https://learn.microsoft.com/en-us/azure/active-directory/develop/howto-create-self-signed-certificate.  

  • A short summary of the above instructions are below:  

# Create a self-signed certificate in PowerShell
$mycert = "eShareApp"
$mycert = New-SelfSignedCertificate -DnsName "eShareApp" -Subject "CN=eShareApp" -CertStoreLocation "Cert:\CurrentUser\My" -NotAfter (Get-Date).AddYears(50) -KeyExportPolicy Exportable -KeySpec Signature -KeyLength 2048 -KeyAlgorithm RSA -HashAlgorithm SHA256
# Extract .key file using OpenSSL
openssl pkcs12 -in eShareApp.pfx -nocerts -nodes -out eShareApp.key
# Extract crt from pfx using OpenSSL
openssl pkcs12 -in eShareApp.pfx -clcerts -nokeys -out eShareApp.crt
# Export certificate to .pfx file
$mycert | Export-PfxCertificate -FilePath eShareApp.pfx -Password $(ConvertTo-SecureString -String "myp@55W0rd" -AsPlainText -Force)
  • When appropriate certificate portions are available, navigate to ‘Manage‘ > ‘Certificates & secrets’

  • In ‘Certificates’ tab, click on ‘Upload certificate’ button. Upload the CRT file from the above steps and click on ‘Add’ at bottom of the open pane.

Collect Items Required for CAS Report

  • M365 Tenant ID: Navigate to ‘Identity > Overview’ tab of the Entra admin console, copy the ‘Tenant ID’ and save it.

  • Application ID: Navigate to ‘Overview’ tab of the application, copy the ‘Application (client) ID’ and save it.

  • Certificate Thumbprint: For the certificate used during application registration process, copy the certificate thumbprint and save it.

  • Private Key: The private key (.key file from above steps) for the certificate uploaded in Entra portal for the application registration.

  • Your Organization’s SharePoint URL: The root URL of your SharePoint tenant, without any site path. Open any SharePoint site, copy the URL, and remove everything after .sharepoint.com Example: If the site URL is https://yourorganization.sharepoint.com/sites/sitename, enter https://yourorganization.sharepoint.com/

  • External third party tools URL: If your organization uses third-party file sharing or collaboration tools, such as Box, Kiteworks, or Dropbox, etc, enter the base URL of each one. eSHARE uses these URLs to detect those links in email and show where content is shared outside Microsoft 365, which adds to the insights in your report. Example: If your organization uses Box, enter https://yourorganization.box.com/

Please provide this information to your eSHARE Customer Success Manager for finalizing the configuration.