Entry Point: Supply Chain Exposure Assessment
Assessment Steps
- OAuth app inventory: Entra ID → Enterprise Applications → list every app users have granted access to. How many did IT approve? How many have mail.read or files.readwrite?
- MSP access audit: What accounts does your MSP have? Domain admin? Global admin? When were the passwords last rotated? Is there MFA?
- Vendor inventory: List every vendor that has access to your data, network, or systems. Categorize: Tier 1 (critical/data access), Tier 2 (operational), Tier 3 (commodity).
- SaaS sprawl discovery: Check M365 admin console, email signup confirmations, credit card statements, browser extension inventory. The real number is 2-4x what IT thinks.
- Browser extension audit: What extensions are installed across the org? Each one has access to browsing data at minimum.
- Software dependency check: If you develop any software, run Grype against your repos. Check GitHub Dependabot alerts.
Output
Third-party risk map: vendor inventory with tier classification, OAuth app inventory with risk ratings, MSP access audit findings, SaaS sprawl report. NIS2 Article 21(d) gap analysis.
- Revoke suspicious OAuth apps in Entra ID — anything with mail.read, mail.send, files.readwrite from an unrecognized publisher
- Enable admin consent workflow in Entra — block users from granting OAuth access without IT approval. One toggle.
- Restrict user consent to verified publishers only: Entra ID → Enterprise Apps → Consent and permissions → "Allow user consent for apps from verified publishers, for selected permissions"
- Rotate MSP account passwords and verify MFA is enabled on every MSP account
- Disable terminated MSP staff accounts — check if former MSP employees still have access to your tenant
- Set Google Alerts for "[critical vendor name] breach" and "[critical vendor name] security incident" for your top 10 vendors
- Run cazadora (open-source) to hunt for suspicious M365 OAuth applications
- Full OAuth app audit: Review every Enterprise Application in Entra. Classify as approved/suspicious/revoke. Document approved apps with owner and business justification.
- MSP access hardening: Convert standing admin access to JIT (Just-in-Time) via Entra PIM. Require phishing-resistant MFA. Name all MSP accounts individually.
- Vendor credential rotation: Rotate all shared credentials, API keys, and service accounts connected to third-party vendors.
Zero unapproved OAuth grants. MSP access is JIT with named accounts and FIDO2 MFA. All vendor credentials rotated and documented. Admin consent workflow enforced.
- Enable Entra audit log alerts for: new OAuth app consent, new Enterprise Application registration, admin role assignments to external accounts
- Monitor MSP login activity — alert on MSP account logins from unexpected locations or outside agreed service windows
- Subscribe to vendor status pages and security advisory feeds for your Tier 1 vendors
- Enable Defender for Cloud Apps OAuth app monitoring (if on M365 E5) — auto-detects risky OAuth grants
- Use Wing Security SaaS Pulse — free SaaS discovery and risk assessment
- SaaS discovery deployment: Full inventory of all SaaS apps, users, and OAuth integrations. Map data flows — which apps have access to what data.
- Continuous vendor monitoring: Google Alerts + SecurityScorecard (free tier for own org) + vendor breach notification monitoring
- Browser extension policy: GPO/Intune policy controlling which extensions are allowed org-wide. Block unapproved extensions.
- Software dependency monitoring: Enable Dependabot/Renovate on all repos. Deploy Socket.dev for behavioral analysis (catches supply chain attacks before CVEs exist).
Every new OAuth grant triggers an alert. MSP access is logged and monitored. Vendor breaches detected within hours via monitoring. SaaS sprawl visible in real time. No shadow integrations.
- Block user OAuth consent entirely for unverified publishers — require admin approval for all new app grants
- Require MFA for all external/guest accounts in your tenant via conditional access
- Review and restrict MSP permissions to least privilege — does the MSP really need Global Admin? Or just Exchange Admin + Intune Admin?
- Enable Entra PIM (Privileged Identity Management) for MSP accounts — JIT access with time limits and approval workflows
- Vendor tiering + security requirements: Tier 1 (critical) = full security assessment + contractual requirements. Tier 2 = abbreviated questionnaire. Tier 3 = self-attestation.
- Contractual security minimums: Encryption, incident disclosure within 24-72 hours, annual pen test, right-to-audit, data deletion on termination.
- Vendor questionnaire process: Use CSA CAIQ (free, 71-300 questions) or CISA Software Acquisition Guide (free web tool).
- Network segmentation for vendor access: Vendor VPN connections terminate in a restricted VLAN. Vendors cannot reach systems beyond their scope.
- API key hygiene: Separate read-only vs. read-write keys per vendor. Rotate on a defined schedule. Revoke on vendor contract termination.
Zero standing vendor admin access. All vendor connections are least-privilege, time-bounded, and logged. Tier 1 vendors assessed annually with contractual security requirements. OAuth consent locked to admin approval only.
- Set quarterly calendar reminder: review all OAuth apps, revoke unused/stale grants
- Set quarterly MSP access review: verify all MSP accounts are current, permissions are correct, terminated staff removed
- Check Have I Been Pwned domain search quarterly for credential exposure
| Cadence | Action | Tool |
|---|---|---|
| Continuous | OAuth consent monitoring | Entra audit logs / Defender for Cloud Apps |
| Continuous | Vendor breach monitoring | Google Alerts + status pages |
| Weekly | Dependency vulnerability alerts | Dependabot / Renovate |
| Monthly | SaaS app review — new apps, unused apps | Wing Security / Entra admin |
| Quarterly | OAuth app audit — revoke stale grants | Entra Enterprise Applications |
| Quarterly | MSP access review | Entra PIM + manual audit |
| Quarterly | Vendor SOC 2 / security posture check | Request from Tier 1 vendors |
| Annually | Full Tier 1 vendor security assessment | CSA CAIQ / CISA tool |
| Annually | Vendor contract security clause review | Legal + procurement |
OAuth grants shrink over time, not grow. MSP access is reviewed and confirmed quarterly. Tier 1 vendors assessed annually. Vendor breach notifications reach the right people within hours. No stale integrations.
- Add security requirements to procurement template — every new vendor contract includes encryption, incident notification, and right-to-audit clauses
- Create the vendor breach response card — one page: who to call, what to revoke, how to assess blast radius (see playbook below)
- Vendor breach response playbook: Tested procedure for when a critical vendor is compromised (see dedicated section below)
- Supplier register: NIS2-compliant inventory of all suppliers with risk classification, last assessment date, data access scope, contract expiry
- Procurement security integration: Security requirements embedded in procurement workflow — no vendor onboarded without minimum security assessment
- Data flow mapping: Document what data goes to which vendors, via which integration, with what access level. Know exactly what's exposed when a vendor is breached.
- Exit strategies: For each Tier 1 vendor, document: how to migrate away, data export procedures, transition timeline, alternative vendors evaluated.
- NIS2 Article 21(d) compliance package: Supply chain security policy, supplier register, procurement criteria, ongoing risk management evidence, coordinated risk assessment participation.
Any vendor compromise has a documented, practiced response. Data flows mapped so blast radius is immediately knowable. Vendor lock-in minimized with documented exit strategies. NIS2 compliant. Insurance evidence ready.
MSP Security Requirements Checklist
| # | Requirement | Why It Matters |
|---|---|---|
| 1 | Named accounts — no shared "[email protected]" | Accountability and audit trail |
| 2 | Phishing-resistant MFA (FIDO2) on all MSP accounts | MSP accounts are high-value targets |
| 3 | Just-in-Time access via Entra PIM — no standing admin | Compromise window minimized to active sessions |
| 4 | Least privilege — Exchange Admin, not Global Admin | Blast radius limitation |
| 5 | Joiner-mover-leaver process for MSP staff changes | Former MSP employees removed promptly |
| 6 | Central logging with 365-day retention of MSP activity + on-host logs (don't rely on defaults — 90 days is minimum, 365 is the target. Supply chain dwell times can be months. Keep logs on-host AND central.) | Forensic capability after compromise |
| 7 | Incident notification within 24 hours | Time is critical in supply chain incidents |
| 8 | Annual penetration test of MSP's own infrastructure | Verify MSP practices what they preach |
| 9 | SOC 2 Type II report reviewed annually | Independent verification of controls |
| 10 | Cyber insurance with adequate coverage | Financial protection if MSP causes incident |
Program Economics (200-seat reference)
| Engagement | Duration | Investment |
|---|---|---|
| Assessment + immediate lockdown | 1–2 days | €1,250 – 2,500 |
| 1 Containment | 1–2 days | €1,250 – 2,500 |
| 2 Detection | 2 days | €2,500 |
| 3 Posture | 2–3 days | €2,500 – 3,750 |
| 4 Vuln Mgmt | 1 day + cadence | €1,250 + €5,000/yr |
| 5 Structural | 2–3 days | €2,500 – 3,750 |
| Full program | 9–13 days | €11,250 – 16,250 + retainer |
Free / Open-Source Tools
- Wing Security SaaS Pulse — Free SaaS discovery + risk
- cazadora — M365 OAuth app hunting
- Syft + Grype — SBOM generation + vuln scanning
- Socket.dev — Supply chain attack detection (free tier)
- Renovate / Dependabot — Automated dependency updates
- CSA CAIQ — Free vendor assessment questionnaire
- CISA Software Acquisition Guide — Free vendor assessment tool
- SecurityScorecard — Free tier for own org rating
- Tines CE — Free security workflow automation
- Have I Been Pwned — Credential exposure monitoring
Quick Reference: OAuth Lockdown
# List all OAuth app consents (PowerShell)
Get-MgServicePrincipal -All |
Get-MgServicePrincipalOauth2PermissionGrant |
Where-Object {
$_.ConsentType -eq "AllPrincipals"
} | Select ResourceId, Scope
# Find apps with mail permissions
Get-MgServicePrincipal -All |
Get-MgServicePrincipalOauth2PermissionGrant |
Where-Object {
$_.Scope -match "Mail|Mail.Read|Mail.Send"
}
# Block user consent for unverified publishers
# Entra Portal:
# Enterprise Apps > Consent and permissions >
# User consent settings >
# "Allow user consent for apps from
# verified publishers, for selected
# permissions"