Skip to content

The 14 Auth0 security checks Black Cat runs

Black Cat SSPM evaluates 14 security policies against your Auth0 configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Auth0 — what access Black Cat needs, and why.

Identity, MFA & sign-in (7)

Third-party & OAuth apps (3)

Other checks (4)

severity: high Role Targets Management API fix difficulty: medium #

Review roles that grant write access to the Auth0 Management API

  1. Open Auth0 Dashboard > User Management > Roles and select the flagged role
  2. Review the Management API permissions (create/update/delete) assigned to it
  3. Remove unnecessary Management API write permissions or reassign members to a scoped role
  4. Confirm the remaining members genuinely require tenant-admin privileges

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

severity: low No Recent Audit Events fix difficulty: easy #

Confirm Auth0 tenant logs are being generated and retained

  1. Open Auth0 Dashboard > Monitoring > Logs and confirm events are present
  2. Verify the M2M application has the read:logs scope
  3. Configure a Log Stream for durable retention if required

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

severity: info Management API Change Event fix difficulty: medium #

Review successful Management API change events for unexpected configuration changes

  1. Open Auth0 Dashboard > Monitoring > Logs and locate the event by its log_id
  2. Confirm the change was authorized and made by an expected administrator
  3. Investigate and revert the change if it was not authorized

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

severity: high Dynamic Client Registration Enabled fix difficulty: easy #

Disable tenant-wide Dynamic Client Registration unless explicitly required

  1. Open Auth0 Dashboard > Settings > Advanced
  2. Disable Enable Dynamic Client Registration
  3. If DCR is required, restrict it with the appropriate promote/scope controls

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial