Open cardosec

Case 7FECE3 · Identity & AD · L3 Applied

Malicious OAuth App Consent

Practise as: Incident drill · Interview

Live alertTwelve users consented to an app called "Docs Viewer Pro" requesting Mail.Read and offline_access. It was published by an unverified tenant yesterday.

Interview questionHow do you respond to an illicit consent grant, and why does resetting passwords not fix it?

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Consent grants the app its own tokens; password resets and MFA do not revoke them, so revoke grants directly
  2. Contain: disable the service principal, remove the grants, revoke user refresh tokens
  3. Scope: audit sign-ins by the app ID and mailbox access logs to see what mail was read or exfiltrated
  4. Prevent: restrict user consent to verified publishers and low-risk scopes; require an admin consent workflow
  5. Notify affected users and check for follow-on phishing sent from their mailboxes

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.