Overview
ContraForce uses a modular application architecture designed around the principle of least privilege. Rather than requesting all permissions through a single application, ContraForce distributes responsibilities across purpose-built enterprise applications registered in your Microsoft Entra ID tenant. Each application only receives the permissions necessary for its specific function. This means you only grant permissions for the capabilities you actually use. For example, if you don’t use Gamebooks to respond to endpoint threats, you never need to consent the ContraForce Gamebooks for MDE application.Quick Reference
Applications by Module
- All Deployments
- Defender Module
- XDR + SIEM Module
Every ContraForce deployment requires these two core applications:
- ContraForce API — Core platform connectivity
- ContraForce Portal — User authentication and portal access
Core Applications
ContraForce API
The core service principal that enables communication between ContraForce services and Microsoft APIs including Microsoft Graph and Azure Resource Manager. This application coordinates all platform operations — from onboarding your workspace to managing Azure resources. App ID:24d97bc0-8f2b-45d5-8e0b-7fe286732ef2
Delegated Permissions
ContraForce Portal
Handles user authentication through Microsoft’s OpenID Connect implementation and retrieves basic profile information for signed-in users. This application enables secure sign-in to ContraForce using your Microsoft work account. App ID:8b7cb435-9526-47ee-b79a-34433f0daad2
Delegated Permissions
Detection & Visibility Applications
ContraForce for MDE (Microsoft Defender for Endpoint)
Provides visibility into Microsoft Defender for Endpoint data, enabling endpoint monitoring, incident ingestion, and threat intelligence display in the ContraForce portal. This application provides device health, alert, and security posture data from Defender for Endpoint. App ID:6efccc6a-f0d3-49e5-92d0-17d4afa9ba52
Requires Microsoft Defender for Endpoint to be deployed and active in the target tenant. Compatible with Microsoft 365 Business Premium, E3, E5, or standalone MDE licenses.
Delegated Permissions
Application Permissions
ContraForce Sentinel Hunting
Calls the Log Analytics API to send direct queries to a Microsoft Sentinel workspace on behalf of the signed-in user. This enables deeper incident context via raw event and evidence logs, and powers the Advanced Hunting page in ContraForce. App ID:6bf1c74d-7ade-4671-a507-166936f89a1f
Only required for the XDR + SIEM module. Not needed for XDR-only deployments.
Delegated Permissions
Response Applications (Gamebooks)
These enterprise applications enable Gamebook response actions. Each application is scoped to a specific entity type, ensuring least-privilege access for automated incident response.ContraForce Gamebooks for MDE
Enables automated response actions targeting endpoint entities, including device isolation, antivirus scans, and file quarantine operations. App ID:ad7b0e79-3c37-4408-bf8f-eb89522cc920
Delegated Permissions (on-behalf-of flows)
Application Permissions (Default)
Enabled Gamebook Actions
ContraForce Gamebooks for Identity
Enables automated response actions targeting user entities, including session invalidation, account lockout, password reset, and MFA reset capabilities. App ID:36b0d51c-4c0f-4810-9cc4-bfbd40c7dd4a
Delegated Permissions (on-behalf-of flows)
Application Permissions (Default)
Application Permissions (Service Provider Password Reset add-on)
These are consented only if a customer enables the optional service-provider password reset add-on (Identity module → Allow service provider to reset passwords). The add-on lets the Reset Password Gamebook run app-only, without an on-behalf-of signed-in user. Enabling it is a customer decision and must be authorized by a Global Administrator or Privileged Role Administrator in the customer tenant.When the add-on is not enabled, Reset Password runs through the delegated (on-behalf-of) flow and requires a signed-in user with sufficient privileges. The modern Graph
resetPassword endpoint does not support application-only calls, so app-only resets use the passwordProfile path enabled by the add-on above.Enabled Gamebook Actions
ContraForce Gamebooks for Email (Microsoft 365 Response)
Facilitates email response actions through the delete email Gamebook. This application can delete malicious emails from user mailboxes and purge phishing messages across the organization. App ID:44dbf6fe-45e3-48a3-bac3-f8d4cf1dba6d
Delegated Permissions
Application Permissions
This application does not have the ability to send email. It requires Microsoft 365 Exchange licenses to be active in the target tenant.
Enabled Gamebook Actions
Managing Users and Groups
Group-to-workspace mapping is managed directly in the ContraForce portal under Settings → User Management. ContraForce no longer provisions a separate User Management enterprise application for group management.Permission Types Explained
ContraForce uses two types of Microsoft Entra ID permissions:
ContraForce enterprise applications are consented with application (app-only) permissions, so response actions can execute in a customer tenant without requiring an operator to be signed in. Because these actions run unattended, operator control is enforced through Gamebook approval gates and a complete audit trail in the Gamebooks History page. A small number of flows use delegated permissions with a signed-in user — for example, password reset runs on-behalf-of by default, unless a customer enables the service-provider password reset add-on, which lets it run app-only via a customer-consented
passwordProfile permission and directory role (see ContraForce Gamebooks for Identity).
Managing Permissions
After onboarding, you can review and manage enterprise application permissions in two locations: From the ContraForce Portal: Navigate to Settings → Permissions to consent additional service principals or review existing consent status. From Microsoft Entra Admin Center: Go to Enterprise Applications to review all ContraForce applications registered in your tenant and their granted permissions.Revoking Consent
If you need to revoke consent for any ContraForce enterprise application:- Go to Azure Portal → Microsoft Entra ID → Enterprise Applications
- Find the ContraForce application you want to revoke
- Click Properties
- Set Enabled for users to sign-in to No (to disable) or Delete the application entirely
Troubleshooting
Related Resources
Audit Permissions
Independently verify enterprise application permissions in your tenant
Platform Onboarding
Step-by-step guide to onboarding your parent workspace
Customer Workspace Onboarding
Onboard customer workspaces with the right modules
Azure Resources Deployed
Complete reference of all Azure resources ContraForce deploys
Roles & Permissions
ContraForce platform roles and what each can do