Supply Chain Security Package

Your Vendors Are Your Attack Surface — Mid-Market Third-Party Risk Management

73%
increase in malicious packages YoY
200-400
SaaS apps in avg mid-market org
48%
of breaches involved a third party (+60% YoY, DBIR 2026)
NIS2 21(d)
mandates supply chain security
Methodology: Supply chain alerts require cross-tenant correlation — a compromised MSP affects hundreds of customers simultaneously. See Investigation Automation for the multi-tenant challenge.
Incident in progress? The response steps are on Vendor Breach Response. This page is how you get ready.
Mid-market supply chain risk is different. You're not building software — you're consuming it. Your attack surface is: the MSP with domain admin, the 200 SaaS apps nobody tracks, the OAuth grants employees click "Allow" on, and the vendor whose breach becomes your breach.
OAuth consent is the shadow supply chain. Every app a user grants access to is a third-party integration you didn't approve. Each one can read email, access files, or impersonate users. Microsoft is restricting user consent defaults in July 2025 — lock this down now.

Entry Point: Supply Chain Exposure Assessment

Map your actual third-party dependency surface. Most mid-market companies are shocked by what they find.
1–2 days Entry point

Assessment Steps

  • OAuth app inventory: Entra ID → Enterprise Applications → list every app users have granted access to. How many did IT approve? How many have mail.read or files.readwrite?
  • MSP access audit: What accounts does your MSP have? Domain admin? Global admin? When were the passwords last rotated? Is there MFA?
  • Vendor inventory: List every vendor that has access to your data, network, or systems. Categorize: Tier 1 (critical/data access), Tier 2 (operational), Tier 3 (commodity).
  • SaaS sprawl discovery: Check M365 admin console, email signup confirmations, credit card statements, browser extension inventory. The real number is 2-4x what IT thinks.
  • Browser extension audit: What extensions are installed across the org? Each one has access to browsing data at minimum.
  • Software dependency check: If you develop any software, run Grype against your repos. Check GitHub Dependabot alerts.

Output

Third-party risk map: vendor inventory with tier classification, OAuth app inventory with risk ratings, MSP access audit findings, SaaS sprawl report. NIS2 Article 21(d) gap analysis.

1 Containment — Lock Down What's Already Exposed
You probably have dozens of OAuth grants nobody approved, MSP accounts with standing admin access, and vendors with stale credentials. Fix the obvious risks today.
Quick Wins (Day 0, Free)
  • Revoke suspicious OAuth apps in Entra ID — anything with mail.read, mail.send, files.readwrite from an unrecognized publisher
    1 hourFree
  • Enable admin consent workflow in Entra — block users from granting OAuth access without IT approval. One toggle.
    15 minFree
  • Restrict user consent to verified publishers only: Entra ID → Enterprise Apps → Consent and permissions → "Allow user consent for apps from verified publishers, for selected permissions"
    15 minFree
  • Rotate MSP account passwords and verify MFA is enabled on every MSP account
    1 hourFree
  • Disable terminated MSP staff accounts — check if former MSP employees still have access to your tenant
    30 minFree
  • Set Google Alerts for "[critical vendor name] breach" and "[critical vendor name] security incident" for your top 10 vendors
    15 minFree
  • Run cazadora (open-source) to hunt for suspicious M365 OAuth applications
    30 minFree / OSS
Core Engagement (1–2 days)
  • Full OAuth app audit: Review every Enterprise Application in Entra. Classify as approved/suspicious/revoke. Document approved apps with owner and business justification.
  • MSP access hardening: Convert standing admin access to JIT (Just-in-Time) via Entra PIM. Require phishing-resistant MFA. Name all MSP accounts individually.
  • Vendor credential rotation: Rotate all shared credentials, API keys, and service accounts connected to third-party vendors.
Target State

Zero unapproved OAuth grants. MSP access is JIT with named accounts and FIDO2 MFA. All vendor credentials rotated and documented. Admin consent workflow enforced.

2 Detection — See Third-Party Risk in Real Time
Know when a new OAuth app is granted, when your vendor gets breached, when your MSP logs in from an unusual location.
Quick Wins (Day 0, Free)
  • Enable Entra audit log alerts for: new OAuth app consent, new Enterprise Application registration, admin role assignments to external accounts
    30 minFree
  • Monitor MSP login activity — alert on MSP account logins from unexpected locations or outside agreed service windows
    30 minFree
  • Subscribe to vendor status pages and security advisory feeds for your Tier 1 vendors
    30 minFree
  • Enable Defender for Cloud Apps OAuth app monitoring (if on M365 E5) — auto-detects risky OAuth grants
    30 minFree (if E5)
  • Use Wing Security SaaS Pulse — free SaaS discovery and risk assessment
    1 hourFree tier
Core Engagement (2 days)
  • SaaS discovery deployment: Full inventory of all SaaS apps, users, and OAuth integrations. Map data flows — which apps have access to what data.
  • Continuous vendor monitoring: Google Alerts + SecurityScorecard (free tier for own org) + vendor breach notification monitoring
  • Browser extension policy: GPO/Intune policy controlling which extensions are allowed org-wide. Block unapproved extensions.
  • Software dependency monitoring: Enable Dependabot/Renovate on all repos. Deploy Socket.dev for behavioral analysis (catches supply chain attacks before CVEs exist).
Target State

Every new OAuth grant triggers an alert. MSP access is logged and monitored. Vendor breaches detected within hours via monitoring. SaaS sprawl visible in real time. No shadow integrations.

3 Posture — Harden Third-Party Access
Every vendor connection is a potential attack path. Minimize what each vendor can access, how long they can access it, and what happens when they're compromised.
Quick Wins (Day 0, Free)
  • Block user OAuth consent entirely for unverified publishers — require admin approval for all new app grants
    15 minFree
  • Require MFA for all external/guest accounts in your tenant via conditional access
    30 minFree
  • Review and restrict MSP permissions to least privilege — does the MSP really need Global Admin? Or just Exchange Admin + Intune Admin?
    1 hourFree
  • Enable Entra PIM (Privileged Identity Management) for MSP accounts — JIT access with time limits and approval workflows
    2 hoursFree (Entra P2)
Core Engagement (2–3 days)
  • Vendor tiering + security requirements: Tier 1 (critical) = full security assessment + contractual requirements. Tier 2 = abbreviated questionnaire. Tier 3 = self-attestation.
  • Contractual security minimums: Encryption, incident disclosure within 24-72 hours, annual pen test, right-to-audit, data deletion on termination.
  • Vendor questionnaire process: Use CSA CAIQ (free, 71-300 questions) or CISA Software Acquisition Guide (free web tool).
  • Network segmentation for vendor access: Vendor VPN connections terminate in a restricted VLAN. Vendors cannot reach systems beyond their scope.
  • API key hygiene: Separate read-only vs. read-write keys per vendor. Rotate on a defined schedule. Revoke on vendor contract termination.
Target State

Zero standing vendor admin access. All vendor connections are least-privilege, time-bounded, and logged. Tier 1 vendors assessed annually with contractual security requirements. OAuth consent locked to admin approval only.

4 Vulnerability Management — Ongoing Third-Party Hygiene
Quick Wins (Day 0, Free)
  • Set quarterly calendar reminder: review all OAuth apps, revoke unused/stale grants
    5 minFree
  • Set quarterly MSP access review: verify all MSP accounts are current, permissions are correct, terminated staff removed
    5 minFree
  • Check Have I Been Pwned domain search quarterly for credential exposure
    10 minFree
Core Engagement (1 day + cadence)
CadenceActionTool
ContinuousOAuth consent monitoringEntra audit logs / Defender for Cloud Apps
ContinuousVendor breach monitoringGoogle Alerts + status pages
WeeklyDependency vulnerability alertsDependabot / Renovate
MonthlySaaS app review — new apps, unused appsWing Security / Entra admin
QuarterlyOAuth app audit — revoke stale grantsEntra Enterprise Applications
QuarterlyMSP access reviewEntra PIM + manual audit
QuarterlyVendor SOC 2 / security posture checkRequest from Tier 1 vendors
AnnuallyFull Tier 1 vendor security assessmentCSA CAIQ / CISA tool
AnnuallyVendor contract security clause reviewLegal + procurement
Target State

OAuth grants shrink over time, not grow. MSP access is reviewed and confirmed quarterly. Tier 1 vendors assessed annually. Vendor breach notifications reach the right people within hours. No stale integrations.

5 Structural — Make Vendor Compromise Survivable
Quick Wins (Day 0, Free)
  • Add security requirements to procurement template — every new vendor contract includes encryption, incident notification, and right-to-audit clauses
    1 hourFree
  • Create the vendor breach response card — one page: who to call, what to revoke, how to assess blast radius (see playbook below)
    1 hourFree
Core Engagement (2–3 days)
  • Vendor breach response playbook: Tested procedure for when a critical vendor is compromised (see dedicated section below)
  • Supplier register: NIS2-compliant inventory of all suppliers with risk classification, last assessment date, data access scope, contract expiry
  • Procurement security integration: Security requirements embedded in procurement workflow — no vendor onboarded without minimum security assessment
  • Data flow mapping: Document what data goes to which vendors, via which integration, with what access level. Know exactly what's exposed when a vendor is breached.
  • Exit strategies: For each Tier 1 vendor, document: how to migrate away, data export procedures, transition timeline, alternative vendors evaluated.
  • NIS2 Article 21(d) compliance package: Supply chain security policy, supplier register, procurement criteria, ongoing risk management evidence, coordinated risk assessment participation.
Target State

Any vendor compromise has a documented, practiced response. Data flows mapped so blast radius is immediately knowable. Vendor lock-in minimized with documented exit strategies. NIS2 compliant. Insurance evidence ready.

MSP Security Requirements Checklist

Your MSP has the keys to everything. If they get breached, you get breached. These are the minimum requirements for any MSP relationship.
#RequirementWhy It Matters
1Named accounts — no shared "[email protected]"Accountability and audit trail
2Phishing-resistant MFA (FIDO2) on all MSP accountsMSP accounts are high-value targets
3Just-in-Time access via Entra PIM — no standing adminCompromise window minimized to active sessions
4Least privilege — Exchange Admin, not Global AdminBlast radius limitation
5Joiner-mover-leaver process for MSP staff changesFormer MSP employees removed promptly
6Central logging with 365-day retention of MSP activity + on-host logs (don't rely on defaults — 90 days is minimum, 365 is the target. Supply chain dwell times can be months. Keep logs on-host AND central.)Forensic capability after compromise
7Incident notification within 24 hoursTime is critical in supply chain incidents
8Annual penetration test of MSP's own infrastructureVerify MSP practices what they preach
9SOC 2 Type II report reviewed annuallyIndependent verification of controls
10Cyber insurance with adequate coverageFinancial protection if MSP causes incident
The test: If your MSP got breached tonight, could you revoke their access within 30 minutes? If not, that's your first action item.

Program Economics (200-seat reference)

EngagementDurationInvestment
Assessment + immediate lockdown1–2 days€1,250 – 2,500
1 Containment1–2 days€1,250 – 2,500
2 Detection2 days€2,500
3 Posture2–3 days€2,500 – 3,750
4 Vuln Mgmt1 day + cadence€1,250 + €5,000/yr
5 Structural2–3 days€2,500 – 3,750
Full program9–13 days€11,250 – 16,250 + retainer
ROI: Average supply chain breach cost: $4.5M. The program costs less than 0.4% of a single incident. NIS2 non-compliance penalties: up to 10M EUR or 2% of global turnover.

Free / Open-Source Tools

Quick Reference: OAuth Lockdown

# List all OAuth app consents (PowerShell)
Get-MgServicePrincipal -All |
  Get-MgServicePrincipalOauth2PermissionGrant |
  Where-Object {
    $_.ConsentType -eq "AllPrincipals"
  } | Select ResourceId, Scope

# Find apps with mail permissions
Get-MgServicePrincipal -All |
  Get-MgServicePrincipalOauth2PermissionGrant |
  Where-Object {
    $_.Scope -match "Mail|Mail.Read|Mail.Send"
  }

# Block user consent for unverified publishers
# Entra Portal:
# Enterprise Apps > Consent and permissions >
# User consent settings >
# "Allow user consent for apps from
#  verified publishers, for selected
#  permissions"
July 2025: Microsoft is restricting default user consent for third-party apps accessing files/sites. Enable admin consent workflow NOW to avoid disruption.