External Microsoft Entra application has administrator-equivalent Azure RBAC rights

Description

A tenant-local service principal for an application registered in an external Microsoft Entra tenant has administrator-equivalent Azure RBAC rights at the tenant root, a management group, or a subscription. Compromise of the external application or its home tenant could allow an attacker to use those rights to control resources and security settings within that scope.

Remediation

Verify that the external enterprise application is trusted and still required, then remove Azure role assignments that grant unnecessary administrator-equivalent permissions. If the application is no longer required, remove its enterprise application from the tenant. For guidance, refer to Remove Azure role assignments and Delete an enterprise application.