ChatGPT in your inbox? Investigating Entra apps that request unexpected permissions


{
   "TenantId": "52672484-b4e1-402d-934c-a8e2fd9b05d1",
   "SourceSystem": "Azure AD",
   "TimeGenerated": "2025-12-02T20:22:16.1185371Z",
   "ResourceId": "/tenants/747930ee-9a33-43c0-9d5d-470b3fb855e7/providers/Microsoft.aadiam",
   "OperationName": "Add service principal",
   "OperationVersion": "1.0",
   "Category": "ApplicationManagement",
   "ResultType": "",
   "ResultSignature": "None",
   "ResultDescription": "",
   "DurationMs": "0",
   "CorrelationId": "f540cbd8-9ec4-4d0e-855c-86e8916c3a1b",
   "Resource": "Microsoft.aadiam",
   "ResourceGroup": "Microsoft.aadiam",
   "ResourceProvider": "",
   "Identity": "Azure ESTS Service",
   "Level": "4",
   "Location": "",
   "AdditionalDetails": [
     {
       "key": "User-Agent",
       "value": "EvoSTS"
     },
     {
       "key": "AppId",
       "value": "e0476654-c1d5-430b-ab80-70cbd947616a"
     },
     {
       "key": "AppOwnerOrganizationId",
       "value": "a48cca56-e6da-484e-a814-9c849652bcb3"
     }
   ],
   "Id": "Directory_f540cbd8-9ec4-4d0e-855c-86e8916c3a1b_XC60C_97530478",
   "InitiatedBy": {
     "user": {
       "displayName": "Azure ESTS Service",
       "id": "1daac687-c3b3-4aad-8111-4bac9568a064",
       "userPrincipalName": "TestUser@ContosoCorp.onmicrosoft.com",
       "ipAddress": "3.89.177.26",
       "roles": []
     }
   },
   "LoggedByService": "Core Directory",
   "Result": "success",
   "ResultReason": "",
   "TargetResources": {
     "id": "07ec4c16-2cc4-4cd7-b6e3-95a9ba007a21",
     "displayName": "ChatGPT",
     "type": "ServicePrincipal",
     "modifiedProperties": [
       {
         "displayName": "AccountEnabled",
         "oldValue": [],
         "newValue": [true]
       },
       {
         "displayName": "AppAddress",
         "oldValue": [],
         "newValue": [
           {
             "AddressType": 0,
             "Address": "http://localhost:5000/hermes/connectors/oauth",
             "ReplyAddressClientType": 1,
             "ReplyAddressIndex": null,
             "IsReplyAddressDefault": false
           },
           {
             "AddressType": 0,
             "Address": "https://platform.api.openai.org/hermes/connectors/oauth",
             "ReplyAddressClientType": 1,
             "ReplyAddressIndex": null,
             "IsReplyAddressDefault": false
           },
           {
             "AddressType": 0,
             "Address": "https://platform.openai.com/hermes/connectors/oauth",
             "ReplyAddressClientType": 1,
             "ReplyAddressIndex": null,
             "IsReplyAddressDefault": false
           },
           {
             "AddressType": 0,
             "Address": "https://tailor.openai.com/api/v1/oauth/callback",
             "ReplyAddressClientType": 1,
             "ReplyAddressIndex": null,
             "IsReplyAddressDefault": false
           },
           {
             "AddressType": 0,
             "Address": "https://connectors.api.openai.com/connector/oauth_callback/ios_relay",
             "ReplyAddressClientType": 1,
             "ReplyAddressIndex": null,
             "IsReplyAddressDefault": false
           },
           {
             "AddressType": 0,
             "Address": "https://chatgpt.com/ccc/o365connector-business-dac4c231-bc0f-4d07-8b4c-3e1f3ee122ae/oauth/callback",
             "ReplyAddressClientType": 1,
             "ReplyAddressIndex": null,
             "IsReplyAddressDefault": false
           },
           {
             "AddressType": 0,
             "Address": "https://chatgpt.com/ccc/o365connector-personal-b9ce8873-ed1f-405d-97b4-51ca6b2a4f3f/oauth/callback",
             "ReplyAddressClientType": 1,
             "ReplyAddressIndex": null,
             "IsReplyAddressDefault": false
           },
           {
             "AddressType": 0,
             "Address": "https://chatgpt.com/connector_platform_oauth_redirect",
             "ReplyAddressClientType": 1,
             "ReplyAddressIndex": null,
             "IsReplyAddressDefault": false
           }
         ]
       },
       {
         "displayName": "AppPrincipalId",
         "oldValue": [],
         "newValue": ["e0476654-c1d5-430b-ab80-70cbd947616a"]
       },
       {
         "displayName": "DisplayName",
         "oldValue": [],
         "newValue": ["ChatGPT"]
       },
       {
         "displayName": "ServicePrincipalName",
         "oldValue": [],
         "newValue": ["e0476654-c1d5-430b-ab80-70cbd947616a","api://e0476654-c1d5-430b-ab80-70cbd947616a"]
       },
       {
         "displayName": "Credential",
         "oldValue": [],
         "newValue": [{
           "CredentialType": 2,
           "KeyStoreId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c",
           "KeyGroupId": "291154f0-a9f5-45bb-87be-9c8ee5b6d62c"
         }]
       },
       {
         "displayName": "ServicePrincipalTag",
         "oldValue": [],
         "newValue": ["WindowsAzureActiveDirectoryIntegratedApp","apiConsumer","webApp"]
       },
       {
         "displayName": "Included Updated Properties",
         "oldValue": null,
         "newValue": "AccountEnabled, AppAddress, AppPrincipalId, DisplayName, ServicePrincipalName, Credential, ServicePrincipalTag"
       },
       {
         "displayName": "TargetId.ServicePrincipalNames",
         "oldValue": null,
         "newValue": "e0476654-c1d5-430b-ab80-70cbd947616a;api://e0476654-c1d5-430b-ab80-70cbd947616a"
       }
     ],
     "administrativeUnits": []
   },
   "AADTenantId": "747930ee-9a33-43c0-9d5d-470b3fb855e7",
   "ActivityDisplayName": "Add service principal",
   "ActivityDateTime": "2025-12-02T20:22:16.1185371Z",
   "AADOperationType": "Add",
   "Type": "AuditLogs"
 },
 {
   "TenantId": "52672484-b4e1-402d-934c-a8e2fd9b05d1",
   "SourceSystem": "Azure AD",
   "TimeGenerated": "2025-12-02T20:22:16.2365366Z",
   "ResourceId": "/tenants/747930ee-9a33-43c0-9d5d-470b3fb855e7/providers/Microsoft.aadiam",
   "OperationName": "Consent to application",
   "OperationVersion": "1.0",
   "Category": "ApplicationManagement",
   "ResultType": "",
   "ResultSignature": "None",
   "ResultDescription": "",
   "DurationMs": "0",
   "CorrelationId": "f540cbd8-9ec4-4d0e-855c-86e8916c3a1b",
   "Resource": "Microsoft.aadiam",
   "ResourceGroup": "Microsoft.aadiam",
   "ResourceProvider": "",
   "Identity": "Azure ESTS Service",
   "Level": "4",
   "Location": "",
   "AdditionalDetails": [
     {
       "key": "User-Agent",
       "value": "EvoSTS"
     },
     {
       "key": "AppId",
       "value": "e0476654-c1d5-430b-ab80-70cbd947616a"
     },
     {
       "key": "AppOwnerOrganizationId",
       "value": "a48cca56-e6da-484e-a814-9c849652bcb3"
     }
   ],
   "Id": "Directory_f540cbd8-9ec4-4d0e-855c-86e8916c3a1b_XC60C_97530533",
   "InitiatedBy": {
     "user": {
       "displayName": "Azure ESTS Service",
       "id": "1daac687-c3b3-4aad-8111-4bac9568a064",
       "userPrincipalName": "TestUser@ContosoCorp.onmicrosoft.com",
       "ipAddress": "3.89.177.26",
       "roles": []
     }
   },
   "LoggedByService": "Core Directory",
   "Result": "success",
   "ResultReason": "",
   "TargetResources": {
     "id": "07ec4c16-2cc4-4cd7-b6e3-95a9ba007a21",
     "displayName": "ChatGPT",
     "type": "ServicePrincipal",
     "modifiedProperties": [
       {
         "displayName": "ConsentContext.IsAdminConsent",
         "oldValue": null,
         "newValue": "False"
       },
       {
         "displayName": "ConsentContext.IsAppOnly",
         "oldValue": null,
         "newValue": "False"
       },
       {
         "displayName": "ConsentContext.OnBehalfOfAll",
         "oldValue": null,
         "newValue": "False"
       },
       {
         "displayName": "ConsentContext.Tags",
         "oldValue": null,
         "newValue": "WindowsAzureActiveDirectoryIntegratedApp"
       },
       {
         "displayName": "ConsentAction.Permissions",
         "oldValue": null,
         "newValue": "[] => [[Id: FkzsB8Qs10y245WpugB6IUdjEXl8YehProtQM5deXYiHxqods8OtSoERS6yVaKBk, ClientId: 07ec4c16-2cc4-4cd7-b6e3-95a9ba007a21, PrincipalId: 1daac687-c3b3-4aad-8111-4bac9568a064, ResourceId: 79116347-617c-4fe8-ae8b-5033975e5d88, ConsentType: Principal, Scope:  Mail.Read offline_access profile openid, CreatedDateTime: , LastModifiedDateTime ]]; "
       },
       {
         "displayName": "TargetId.ServicePrincipalNames",
         "oldValue": null,
         "newValue": "e0476654-c1d5-430b-ab80-70cbd947616a;api://e0476654-c1d5-430b-ab80-70cbd947616a"
       }
     ],
     "administrativeUnits": []
   },
   "AADTenantId": "747930ee-9a33-43c0-9d5d-470b3fb855e7",
   "ActivityDisplayName": "Consent to application",
   "ActivityDateTime": "2025-12-02T20:22:16.2365366Z",
   "AADOperationType": "Assign",
   "Type": "AuditLogs"
 }



Source link