SOC playbook for OAuth client ID spoofing detection
🔎 This article explains how OAuth client ID spoofing can evade per-application volume thresholds by rotating or fabricating the client ID field, turning valid credential checks into stealthy attacks. It outlines key Entra ID error codes (AADSTS50034, AADSTS50126, AADSTS700016) and shows why AADSTS700016 paired with many distinct client IDs is a critical triage signal. The piece describes two large campaigns that produced millions of spoofed IDs, provides a Kusto detection query to correlate cardinality and error sequences, and recommends a short response runbook (reset, revoke, review) plus long-term mitigation by retiring ROPC.