SSO and Entra in a web app security review
Guest invites beat shared passwords. What to grant a tester on an Entra- or Google-fronted SaaS app without handing over the keys.
If the product lives behind SSO and Entra, the identity layer is part of the app.
A web application security review that skips login is a review of a brochure.
Short answer: Grant a guest or test user. Name whether Google, Entra, or a custom session is in scope. I still charge $2,400 for one app. Clock starts when that user can sign in.
What to grant
A low-privilege user that looks like a customer. A second role if you have one. No global admin. No production break-glass.
Revoke both after the free retest window.
What I look at
Invite and reset. Role mapping after the IdP assertion. Session cookies and tokens the UI stores. Whether a user from tenant A can open tenant B.
I will not ask you to paste a client secret into a ticket. The sample shows how auth findings are written.
FAQ
Can you review an app behind Entra? +
Yes, when you grant a guest or test user and say SSO is in scope. I do not need a global admin.
Is a shared password acceptable? +
It works. A guest invite is cleaner and easier to revoke after the retest.
Does SSO change the price? +
Not for one application. $2,400, $1,200 to start. Extra apps are quoted.