Complete reference of all Azure resources, enterprise applications, and role assignments provisioned during ContraForce onboarding.
This article documents all Azure resources that ContraForce provisions during the onboarding process. Use this reference to understand what’s deployed in your environment, verify deployments, and plan for offboarding if needed.
The resources deployed depend on your module selection (XDR vs XDR + SIEM) and whether you enable AI Agents. Not all resources apply to every deployment.
These applications are provisioned and consented during initial setup:
Application
Application ID
Purpose
ContraForce API
24d97bc0-8f2b-45d5-8e0b-7fe286732ef2
Core platform API access
ContraForce Portal
8b7cb435-9526-47ee-b79a-34433f0daad2
User authentication and portal access
These two applications are required for all ContraForce deployments, regardless of module selection. They are consented when you first sign in at portal.contraforce.com, as separate ContraForce API and ContraForce Portal Microsoft consent prompts granted by a Global Administrator.
Consent model. ContraForce enterprise applications are consented with application (app-only) Microsoft Graph permissions. Admin consent for Microsoft Graph application permissions must be granted by a Global Administrator — Cloud Application Administrator and Application Administrator cannot grant it. Global Administrator is required for the one-time consent only and is not retained; activate it just-in-time with Privileged Identity Management (PIM) and deactivate afterward.Because actions run as the application (no signed-in user required), operator control is enforced through Gamebook approval gates — only Workspace Owners can approve high-impact actions — and a complete audit trail in the Gamebooks History page.
Cross-tenant visibility into your Sentinel workspace
Incident management without logging into your tenant
Centralized management for MSSPs
Azure Lighthouse delegates Azure resource access only (Sentinel Contributor + Reader on the Sentinel resource group). It does not delegate identity, mailbox, or endpoint response. Those capabilities are provided by the consented ContraForce enterprise applications in each tenant — through per-tenant application consent, or GDAP for CSP relationships. Azure Lighthouse is distinct from Microsoft 365 Lighthouse and from GDAP.
Azure Lighthouse is the Microsoft-recommended approach for MSSP scenarios. It provides secure delegated access without sharing credentials or creating guest accounts.