Application Proxy

Application Proxies allow access to on-prem web applications after sign-in to Entra ID. They have the following components:

  • Endpoint; external URL that the users browse to access the on-prem application. External users must authenticate to AAD

  • Application proxy service. This service runs in the cloud and passes the token provided by Entra ID to the on-prem connector

  • Application Proxy Connector - Agent that runs on the on-prem infra and acts as a communication agent between the cloud proxy service and on-prem app.

Enumerate Application Proxies

Script:

Vulnerabilities

Most applications behind a proxy are most-likely old or important applications. Web vulnerabilities do not magically go away, so if there is such a vulnerability in the web-app, it may be exploited.

Last updated