Skip to content

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Microsoft 365, Microsoft Entra ID, Exchange Online and Microsoft Purview are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.

Glossary

Illicit consent grant

An attack in which a user or admin is tricked into granting an attacker's OAuth application access to mail, files or the directory, bypassing password and MFA.

An illicit consent grant (or consent phishing) happens when someone approves an OAuth consent prompt for an attacker-controlled application. The app then receives delegated or application permissions, for example Mail.ReadWrite, Mail.Send, Files.ReadWrite.All and offline_access, and accesses data with its own tokens. Resetting the user's password or enforcing MFA does not remove that access.

Evidence is in the Entra audit log and the Unified Audit Log: Consent to application, Add delegated permission grant, Add app role assignment to service principal, often with Add service principal. The ModifiedProperties show the scopes and whether it was admin consent. Remediation means removing the grant, deleting the service principal and restricting user consent. MITRE ATT&CK: T1528.

See illicit consent grant investigation.