Case 7FECE3 · Identity & AD · L3 Applied
Malicious OAuth App Consent
Practise as: Incident drill · Interview
Live alertTwelve users consented to an app called "Docs Viewer Pro" requesting Mail.Read and offline_access. It was published by an unverified tenant yesterday.
Interview questionHow do you respond to an illicit consent grant, and why does resetting passwords not fix it?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Consent grants the app its own tokens; password resets and MFA do not revoke them, so revoke grants directly
- Contain: disable the service principal, remove the grants, revoke user refresh tokens
- Scope: audit sign-ins by the app ID and mailbox access logs to see what mail was read or exfiltrated
- Prevent: restrict user consent to verified publishers and low-risk scopes; require an admin consent workflow
- Notify affected users and check for follow-on phishing sent from their mailboxes
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.