Back to results

Entra ID End-User Consent to Application with High-Risk Delegated Scopes

Identifies an end-user (non-admin) consent grant in Microsoft Entra ID to an application requesting delegated scopes commonly abused in illicit consent grant (OAuth phishing) attacks, such as mail, mailbox settings,…

Description

Identifies an end-user (non-admin) consent grant in Microsoft Entra ID to an application requesting delegated scopes commonly abused in illicit consent grant (OAuth phishing) attacks, such as mail, mailbox settings, contacts, files, SharePoint, OneNote, Teams chat and Exchange Web Services. Graph scopes are evaluated together with offline_access, which returns a long-lived refresh token and gives an attacker-controlled application durable, silent access to the victim's data without stealing a password or re-prompting for MFA. The alert classifies the application owner as Microsoft first-party, in-tenant or external to help prioritize review.

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detection requirements

Platform
ContainersIaaSIdentity ProviderLinuxmacOSOffice SuiteSaaSWindows

The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.

Known benign triggers

  • Onboarding of a sanctioned mail client, add-in, backup, archiving, CRM, calendar or SharePoint application that legitimately requires delegated access with a refresh token. Validate publisher verification, application ownership (Esql.app_owner_type) and whether the scopes align with an approved business use case, then add an exception for the reviewed application. Microsoft first-party developer tooling such as Graph Explorer or Microsoft Graph Command Line Tools may legitimately request mailbox or file scopes when used by IT staff. Restricting end-user consent to verified publishers and low-risk permissions reduces this residual set to unsanctioned applications only.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice