Skip to content
Benchmarks

redact-secret · Report · Detector

Microsoft Entra client secrets

  • 45 fixtures
  • Format evidence: T1 · Provider-documented
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

  • Provider documentation Graph PowerShell Add-MgApplicationPassword SecretText examples (3 + 8Q~ + 34) · observed 2026-09-23 · Microsoft Graph PowerShell's Add-MgApplicationPassword reference (learn.microsoft.com) prints two example SecretText values, each 3 characters (equal to the printed 3-character Hint), the digit 8, the literal Q~, and 34 characters, 40 in total. The Q~ marker at offset 4 and the 8-variant's 40-character width come from these examples, not from a stated grammar. The 7Q~ 37-character previous format, the digit-to-length coupling and the body alphabet are corroborated only by Microsoft's security-utilities code (SEC101/156) and third-party tools
  • trufflehog 3.97.4
  • gitleaks 8.30.1
  • Twin source Purview Entra client secret definition · observed 2026-09-22 · learn.microsoft.com states the client secret is "a combination of up to 40 characters" of letters, digits, "-", "_", "." and "~". It backs a length twin (41 characters) only; the digit+Q~ marker is example- and tool-corroborated (redact-secret#655) and the positive tier is unchanged

Re-tiered 2026-09-23 (#112, provider evidence redact-secret#655). T1 rests on a provider-domain SDK-reference example, not a prose grammar: no Microsoft page states the format in prose, and a Graph SDK maintainer calls the two values "examples in the documentation", not issued secrets. Accepting an SDK-reference example as the T1 source is a maintainer ruling, on the same footing as the google-api-key example precedent (and terraform-cloud-token/supabase-management-token before it), not a change to the T1 bar. Retained limitations the provider examples do not settle: the pattern accepts any marker digit where the provider shows only 8 (and Microsoft code only 7|8); it accepts 37-40 characters with any digit where SEC101/156 couples 7Q~ to exactly 37 and 8Q~ to exactly 40; and other Microsoft pages disagree without describing the Q~ format (Graph passwordCredential/addPassword say "16-64 characters" with a legacy 32-character markerless example, Purview says "up to 40" with no Q~). redact-secret-benchmarks#161 (following redact-secret#655's web-search pass) found the 3-character lead excluded "-", a false negative: portal- and CLI-issued secrets starting with "-" are real (four independent reports, one measured at 8Q~/40, including one that breaks `az login -p`), TruffleHog 3.97.4's azure_entra/serviceprincipal/v2 detector (merged 2024-11-20; the earlier review only checked v1, which has no Q~ marker) already accepts "-" in the lead, and Microsoft's own scanner rule (microsoft/security-utilities SEC101/156 — provider code, not documentation) agrees. Widened to match; gitleaks's azure-ad-client-secret rule still excludes "-", so it stays cited for the marker only. Product main detects the leading-dash shape since redact-secret#707 (fix dc855b6; known gap product-707 fixed); the published 0.1.0-beta.6 package still misses it. The marker-digit and length-coupling points stay open as separate precision issues under #161, not fixed here.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of Microsoft Entra client secrets fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Tool-corroborated22False alarmsat most 14.9%0 of 22 controls flagged22 quiet · 0 flagged
  • flare-redact at most 14.9%
  • gitleaks at most 14.9%
  • trufflehog at most 14.9%
Must not flag · Project policy3False alarmsinsufficient-evidence0 of 3 controls flagged3 quiet · 0 flagged
  • flare-redact insufficient-evidence
  • gitleaks insufficient-evidence
  • trufflehog insufficient-evidence
Must redact · Provider-documented20Secret spans left readableat most 16.1%0 of 20 spansNear-twins told apartat least 81.6%17 of 17 pairs20 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 100.0%
  • gitleaks at most 36.0%
  • trufflehog at most 16.1%
45 of 45 rows
Fixtures
45
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

45 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Microsoft Entra client secrets
FixtureKind and evidenceredact-secret
microsoft-entra-client-secret-appsettings-azureadmicrosoft-entra · documented-format-literalMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-az-ad-sp-create-for-rbacmicrosoft-entra · documented-format-literalMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-az-login-service-principalmicrosoft-entra · documented-format-literalMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-bommicrosoft-entra · multibyte-text-offsetsMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-client-secret-credential-csharpmicrosoft-entra · documented-format-literalMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-compose-environmentmicrosoft-entra · documented-format-literalMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-digit-q-tilde-baremicrosoft-entra · documented-format-literalMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-digit-q-tilde-quotedmicrosoft-entra · documented-format-literalMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-digit-q-tilde-unicode-crlfmicrosoft-entra · documented-format-literalMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-env-client-secretmicrosoft-entra · documented-format-literalMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-jsonmicrosoft-entra · structured-text-valueMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-leading-dash-baremicrosoft-entra · documented-format-literalMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-leading-dash-quotedmicrosoft-entra · documented-format-literalMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-leading-dash-unicode-crlfmicrosoft-entra · documented-format-literalMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-markdownmicrosoft-entra · markdown-and-comment-valueMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-no-final-newlinemicrosoft-entra · value-at-input-edgesMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-pythonmicrosoft-entra · source-code-string-literalMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-single-quotesmicrosoft-entra · quoted-value-extentMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-tomlmicrosoft-entra · structured-text-valueMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-yamlmicrosoft-entra · structured-text-valueMust redactT1 · Provider-documentedRedacted
microsoft-entra-client-secret-bom-twinmicrosoft-entra · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-credential-listing-public-idmicrosoft-entra · public-identifierMust not flagT2 · Tool-corroboratedQuiet
microsoft-entra-client-secret-digit-q-tilde-bare-twinmicrosoft-entra · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-digit-q-tilde-marker-bare-twinmicrosoft-entra · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-digit-q-tilde-marker-quoted-twinmicrosoft-entra · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-digit-q-tilde-marker-unicode-crlf-twinmicrosoft-entra · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-digit-q-tilde-quoted-twinmicrosoft-entra · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-digit-q-tilde-unicode-crlf-twinmicrosoft-entra · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-json-twinmicrosoft-entra · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-label-prosemicrosoft-entra · benign-lookalikeMust not flagT3 · Project policyQuiet
microsoft-entra-client-secret-leading-dash-bare-twinmicrosoft-entra · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-leading-dash-missing-markermicrosoft-entra · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
microsoft-entra-client-secret-leading-dash-quoted-twinmicrosoft-entra · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-leading-dash-short-suffixmicrosoft-entra · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
microsoft-entra-client-secret-leading-dash-unicode-crlf-twinmicrosoft-entra · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-markdown-twinmicrosoft-entra · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-maskmicrosoft-entra · benign-lookalikeMust not flagT3 · Project policyQuiet
microsoft-entra-client-secret-missing-markermicrosoft-entra · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
microsoft-entra-client-secret-no-final-newline-twinmicrosoft-entra · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-python-twinmicrosoft-entra · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-referencemicrosoft-entra · benign-lookalikeMust not flagT3 · Project policyQuiet
microsoft-entra-client-secret-short-suffixmicrosoft-entra · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
microsoft-entra-client-secret-single-quotes-twinmicrosoft-entra · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-toml-twinmicrosoft-entra · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
microsoft-entra-client-secret-yaml-twinmicrosoft-entra · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet