ENTRALOGIC
KF

22 checks · 18 evaluated · 4 not evaluated

B5High4 groups

Third-party apps with write access to the directory

Four applications can change directory objects without any approval step. Consent was granted once, by one person, and it does not expire.

Evidence

ApplicationPermissionConsented byConsentedLast used
HR Sync ConnectorUser.ReadWrite.Alladm.jsandvik@vestholm.no09 Jan 202420 Aug 2026
Printer Fleet ManagerDevice.ReadWrite.Alladm.kfloen@vestholm.no22 May 202417 Aug 2026
Legacy IntranetGroup.ReadWrite.Alladm.legacy@vestholm.no03 Oct 2022
Onboarding FormsUser.ReadWrite.Alladm.jsandvik@vestholm.no14 Feb 202512 Aug 2026

After upgrading, Entra Logic appears in this list. That is correct, and it is the point: write access moves from people to one service that can only do what an approved order asks for. The full permission list is on the security page.

How this was derived

servicePrincipal.appRoleAssignments contains '*.ReadWrite.All'
AND servicePrincipal.tags != 'internal'
Service principals read
144
Holding write permissions
4

If closed

+2 points1 unused consent revoked3 consents documented with an owner

Fix

Revoke the consent nothing has used since 2022, and record a named owner and a review date against the three that remain.

requires write access

Related findings

Sample report. Fictional group, fictional data.