Skip to main content

Understanding Enterprise Applications

Before ContraForce can protect your organization, specific Microsoft Entra ID permissions must be granted to enable secure communication between ContraForce services and your Microsoft environment. This article explains the enterprise applications deployed during onboarding and the permissions each requires.

Getting Started

ContraForce Portal: portal.contraforce.com

Required Roles for Onboarding

To complete the ContraForce onboarding process and consent to the required enterprise applications, the following roles must be assigned to the user performing the onboarding:
If your organization separates these roles across different users, coordinate with both administrators to complete the onboarding process.
Consent model. ContraForce enterprise applications are consented with application (app-only) Microsoft Graph permissions. Admin consent for Microsoft Graph application permissions must be granted by a Global Administrator — Cloud Application Administrator and Application Administrator cannot grant it. Global Administrator is required for the one-time consent only and is not retained; activate it just-in-time with Privileged Identity Management (PIM) and deactivate afterward.Because actions run as the application (no signed-in user required), operator control is enforced through Gamebook approval gates — only Workspace Owners can approve high-impact actions — and a complete audit trail in the Gamebooks History page.

Overview of ContraForce Enterprise Applications

ContraForce uses a modular application architecture designed around the principle of least privilege. Rather than requesting all permissions through a single application, ContraForce distributes responsibilities across purpose-built enterprise applications. This approach ensures that each application only receives the permissions necessary for its specific function. When you onboard with ContraForce, the following enterprise applications are registered in your Microsoft Entra tenant:

Initial Registration

  1. Navigate to portal.contraforce.com
  2. Click Register with Microsoft
  3. Sign in with your Microsoft Work account (must have the Global Administrator role to grant admin consent for the service principals; Subscription Owner also needed for Sentinel and Agent Center)
  4. Consent to the ContraForce API permissions
  5. Consent to the ContraForce Portal permissions
The ContraForce API and ContraForce Portal consents appear as two separate Microsoft consent prompts. After these core app consents are granted, you configure module-specific permissions per workspace from the Modules tab.

Additional Permissions

After initial onboarding, additional enterprise application permissions can be configured from Settings → Permissions within the ContraForce portal based on the features your organization requires.

Enterprise Application Details

ContraForce API

The ContraForce API is the core service principal that enables communication between ContraForce services and Microsoft APIs including Microsoft Graph and Azure Resource Manager.

ContraForce Portal

The ContraForce Portal service principal handles user authentication through Microsoft’s OpenID Connect implementation and retrieves basic profile information for signed-in users.

ContraForce Sentinel Hunting

This service principal enables direct queries to your Microsoft Sentinel workspace for incident investigation and advanced hunting capabilities.

ContraForce for MDE

This service principal provides visibility into Microsoft Defender for Endpoint data, enabling endpoint monitoring and threat intelligence display in the ContraForce portal.

ContraForce Gamebooks for Identity

This service principal enables automated response actions targeting user entities, including session invalidation, account lockout, and password reset capabilities.
Delegated Permissions (on-behalf-of flows)Application Permissions (Default)
Application permissions allow ContraForce to execute Gamebook actions without requiring a service provider user to be signed in. Password reset runs on-behalf-of (delegated) by default; enabling the optional service-provider password reset add-on lets it run app-only via a customer-consented permission and an Authentication Administrator directory role. See the Enterprise Applications Reference.

ContraForce Gamebooks for MDE

This service principal enables automated response actions targeting endpoint entities, including device isolation, antivirus scans, and file quarantine operations.
Delegated Permissions (on-behalf-of flows)Application Permissions (Default)
Application permissions enable service providers to execute endpoint response actions in customer tenants without requiring a user to be actively signed in.

Why This Architecture?

ContraForce’s modular application architecture provides several benefits:
  • Principle of Least Privilege — Each application only requests the permissions necessary for its specific function
  • Granular Control — Organizations can enable only the features they need without granting unnecessary permissions
  • Reduced Friction — Service providers can onboard customers incrementally based on their security maturity
  • Improved Security Posture — Limiting permissions reduces potential attack surface

Managing Permissions

After onboarding, you can review and manage ContraForce enterprise application permissions in two locations:
  1. ContraForce Portal: Navigate to Settings → Permissions to consent to additional service principals
  2. Microsoft Entra Admin Center: Review enterprise applications and their granted permissions under Enterprise Applications
For questions about specific permissions or to request changes to your ContraForce configuration, contact your ContraForce support: support@contraforce.com.