Summary

"Claims-Portal" is an internal web application that has been running since before anyone used the word tenant. It sits on a server in a datacentre, it authenticates against something old, and today anybody on the corporate network can reach it on port 443 because that is what corporate networks were for. It is also the last node on an attack path that Exposure Management has been quietly drawing for months. A flat network is a graph in which one compromised credential has an edge to everything, and an attack path is a graph in which a handful of specific edges lead somewhere expensive. Read them that way and the controls stop being a shopping list. Each one deletes a particular kind of edge, some of them delete fewer than the diagram suggests, and knowing which is which is the difference between a programme and a backlog.

Reachability is an Edge

Replacing network reachability with per-app access is the strongest structural move you can make. A user who needs "Claims-Portal" gets a connection to "Claims-Portal", brokered and evaluated, and gains no route to the forty other things sharing that subnet. The edge from credential to subnet is deleted outright rather than monitored, which is a category of improvement that detection cannot match.

The qualification is that this is delivered by software running on the endpoint, and the coverage follows the software rather than the intention.

Figure 1. – Describes three populations, three different security postures, one project that was reported as complete.
Figure 1. – Describes three populations, three different security postures, one project that was reported as complete.

Three specifics are worth writing into a design document rather than discovering later. Connecting through the Global Secure Access client is required to acquire Private Access traffic at all, so an unenrolled or unmanaged machine simply takes the old path. Remote network connectivity, the branch office option, carries the Microsoft traffic and Internet Access forwarding profiles, and Conditional Access policies for that traffic are only enforced when the user also has the client. And the compliant network check, which is the control that lets a policy insist a session arrived through your tunnel, is not currently supported for Private Access applications.

That last one deserves a moment because it is counterintuitive. The private applications are the ones you tunnelled deliberately, and they are the ones where the tunnel cannot yet prove itself as a Conditional Access condition. It does not make Private Access weak. It means the assurance for "Claims-Portal" comes from the fact that no network route exists rather than from a signal you can write a policy against, and those are different arguments to make to an auditor.

 

The Token Edge

Imagine somebody leaves at 2:05 and their token is still good at 2:59. What happens next:

Event How it reaches the resourceWhat it depends on
Account disabledA critical event, evaluated by the resource against the presented token, near real timeThe client having declared cp1. Without it there is no claims challenge and no revocation until expiry.
Risk spikeEntra ID Protection raises the user to high, which is a critical eventEntra ID P2, and the detection having actually fired. Several of the useful ones are offline.
Location changeThe resource compares the caller's IP against the Conditional Access policyThe resource seeing the same IP the token service saw. Where they differ, Entra issues a one hour token and does not enforce location change during it.

Table 1 – Describes three events, three different dependency chains. Only the first is as immediate as the slide implies.

 

The IP mismatch case is the one that matters here, because it is caused by the network rather than by identity. Split tunnels, proxies and consumer VPNs all produce it. Strict location enforcement removes that grace period for organisations with stable, known egress, which is a good trade if you have already done the work in the previous section and a painful one if you have not. The order matters: route the traffic first, then tighten the enforcement that depends on knowing where traffic comes from.

 

Paths, Not Piles

Figure 2. – Describes the pile as real work. The argument is only about which three squares get done this quarter.
Figure 2. – Describes the pile as real work. The argument is only about which three squares get done this quarter.

Exposure Management generates paths from the data it already holds across Defender for Endpoint, Defender for Identity, Defender for Cloud and Entra ID, then simulates how an attacker would traverse them. Where several paths intersect on their way to a critical asset, that node is a choke point, and fixing it closes every path running through it rather than the one you happened to be looking at.

 

This is where the ranking quietly depends on you. There is a predefined catalogue of critical asset classifications covering devices, identities and cloud resources, and it is genuinely good. It does not know that "Claims-Portal" holds the thing your regulator asks about. Until somebody creates a custom classification for it, every path calculation is answering a question about Microsoft's idea of your crown jewels rather than yours. Classifying critical assets is a business exercise disguised as a product configuration, and it is the step most often skipped.

 

The graph is queryable, which is what makes this more than a dashboard. Two tables carry it, and the edge labels are the interesting part: values like affecting, routes traffic to, is running and contains describe relationships that no single product owns.

Figure 3. – Describes the choke point in most real graphs is an application object, which is nobody's standing agenda item
Figure 3. – Describes the choke point in most real graphs is an application object, which is nobody's standing agenda item

What Each Control Deletes

Reading the whole series as edge deletion makes the controls comparable for the first time. Phishing-resistant authentication removes edges that start at a person. Per-app access removes edges made of network reachability. Trimming an OAuth scope removes edges made of delegated authority, which is the category people forget because it has no physical analogue. Privileged Identity Management shortens the time an edge exists rather than removing it, and continuous access evaluation does the same thing to the token edge.

Figure 4. – Shows the same controls, expressed in one unit. This is the version of the slide that survives a steering committee.
Figure 4. – Shows the same controls, expressed in one unit. This is the version of the slide that survives a steering committee.

SaaS posture management runs alongside this rather than inside it, producing one ranked list across every connected application, and its value is that it covers the estate where nobody has a network diagram at all. Treat its output as another source of edges rather than another queue of findings, and it lands in the same prioritization conversation instead of competing with it.

What to do First

Classify the critical assets before deploying anything. It takes a workshop and it changes every number that follows, because path ranking without it is ranking against a generic idea of importance. Then look at the choke points rather than the top-ranked paths, and expect at least one of them to be an application registration that no team currently owns. Deciding who owns that object is worth more than the next three findings, and it is a conversation about organizational design rather than configuration, which is exactly why it keeps getting deferred.

Conclusion

The network stopped being a boundary and became an edge like any other, which is a promotion for identity and a demotion for the firewall. Per-app access deletes the reachability edge to "Claims-Portal" for everyone running the client, and changes nothing for everyone who is not. Count what you removed in paths rather than findings, classify your own crown jewels before letting a product rank them, and go looking for the choke point that two teams both assumed the other one owned.