azure-entra-application-client-secret-create-response

addPassword returns the new application secret exactly once and it can leak from provisioning output.

azurecritical service: azure:entra emits ExposesCredential

Where it sits

locationmicrosoft.graph.passwordCredential.secretText
location kindsecret_value
data kindscredential password
emits edgeExposesCredential
serviceEntra ID (azure:entra)

Collection recipe

access modecreation_response_only
operationPOST /applications/{application-id}/addPassword
response pathsecretText
encodingjson
params{"application-id": "\u003capplication-id\u003e"}

Required permissions

Application.ReadWrite.All

References

move · open · esc close