OAuth consent phishing tricks a Microsoft 365 user into approving a malicious third-party app instead of handing over a password. Once that app is approved, it gets a token that can read mail, files, or calendar data for as long as the approval stands, even after you reset the password or require MFA. Microsoft’s own security team documented a campaign using exactly this method against SaaS-connected accounts between mid-2025 and mid-2026, and the trick works as well on a twelve-person Fort Myers accounting office as it does on a large enterprise.
- OAuth consent phishing bypasses passwords and MFA by getting a user to approve a malicious app’s permission request, not by stealing login credentials.
- A phone call impersonating IT support is one of the two main ways attackers get employees to click “Accept” on a rogue app.
- Once an app is authorized, it keeps its access until someone finds it and revokes it, a step most small businesses never take.
- Microsoft 365 has a built-in admin consent workflow that stops employees from approving risky apps on their own.
- A short quarterly check of connected apps in the Entra admin center catches most of this before it becomes a real problem.
What is OAuth consent phishing, exactly?
Every time you connect a scheduling tool, a CRM plugin, or a mail-merge add-in to Microsoft 365, you’re walking through an OAuth consent screen. That screen lists what the app wants to do, read your mail, see your contacts, write to your calendar, and asks you to approve it. Legitimate apps use this process constantly. Attackers abuse the same process by registering an app with a convincing name, often mimicking a tool your business already trusts, and pushing employees toward that same approval screen.
Once a user clicks “Accept,” Microsoft issues the app an access token. That token is not the user’s password. It’s a separate credential scoped to whatever permissions were granted, and it stays valid independent of the user’s own login sessions. Microsoft’s July 2026 write-up on a ShinyHunters-linked campaign describes attackers registering apps disguised as tools like “Salesforce Data Loader” to get exactly this kind of standing access to Salesforce-connected Microsoft 365 environments.
Why does it work even with MFA turned on?
Multi-factor authentication protects the login step: proving the person typing the password is who they say they are. OAuth consent happens after that. The user is already logged in, already past MFA, and is just being asked to approve an app’s request for data access. A password reset doesn’t touch the token the app already holds, and MFA was never part of that transaction in the first place. That’s why security teams describe illicit consent grants as a gap that normal credential hygiene doesn’t close.
How are attackers getting SMB employees to approve these apps?
Microsoft’s analysis of the mid-2025 to mid-2026 campaign points to two main paths. The first is voice phishing: someone calls pretending to be IT support and walks an employee through “verifying” their account, which really means approving a malicious app. The second is supply chain compromise, where attackers ride in through a breach at a tool your business already integrates with. Microsoft names a Salesloft Drift credential compromise from August 2025 and a separate Klue incident in June 2026 as entry points attackers used to reach downstream Salesforce and Microsoft 365 tenants through trusted OAuth connections.
If that vishing pattern sounds familiar, it should. It’s the same social engineering playbook behind the help desk impersonation calls we’ve covered before for Southwest Florida businesses: a confident caller, urgency, and a request dressed up as routine IT maintenance.
What can a small business do about it today?
You don’t need an enterprise security team to close most of this gap. A handful of settings and a recurring habit cover the bulk of the risk:
Turn on the admin consent workflow in the Microsoft Entra admin center so employees can’t approve apps requesting elevated permissions on their own; requests route to an admin for review instead. Microsoft’s own documentation on configuring the admin consent workflow walks through the setup, and it takes a Global Administrator about ten minutes.
Restrict user consent to verified publishers with low-risk permissions, rather than leaving it wide open. Review the Enterprise applications list in the admin center on a schedule, not just when something looks wrong, and revoke anything you don’t recognize or no longer use. If you’ve already worked through our Microsoft 365 cybersecurity checkup, add connected-app review as a line item alongside it. Tell staff plainly that IT support, internal or outsourced, will never call and ask them to approve an application to “verify” their account.
Frequently asked questions
Does resetting my password stop OAuth consent phishing?
No. The malicious app’s access token is separate from the user’s password and keeps working until an administrator finds the app in the Enterprise applications list and revokes its permissions.
How do I see which apps have access to our Microsoft 365 account?
In the Microsoft Entra admin center, go to Enterprise applications under Identity, then Consent and permissions, to see every app with granted access and who approved it.
Is this different from a regular phishing email?
Yes. A typical phishing email tries to steal a password directly. Consent phishing asks the user to approve an app’s permission request, which sidesteps the password and MFA entirely once granted.
How often should we review connected apps?
Quarterly at a minimum, and immediately after any employee reports a suspicious call or email asking them to “verify” their Microsoft 365 account.
If you’re not sure what’s currently connected to your business’s Microsoft 365 tenant, that’s worth finding out before an attacker does. SWFIT offers a free 15-minute IT and security review for Southwest Florida businesses to check exactly this kind of exposure. Reach out to schedule yours.
Southwest Florida IT