Entra ID End-User Consent to Application with High-Risk Delegated Scopes
Identifies an end-user (non-admin) consent grant in Microsoft Entra ID to an application requesting delegated scopes commonly abused in illicit consent grant (OAuth phishing) attacks, such as mail, mailbox settings,…
Description
Identifies an end-user (non-admin) consent grant in Microsoft Entra ID to an application requesting delegated scopes commonly abused in illicit consent grant (OAuth phishing) attacks, such as mail, mailbox settings, contacts, files, SharePoint, OneNote, Teams chat and Exchange Web Services. Graph scopes are evaluated together with offline_access, which returns a long-lived refresh token and gives an attacker-controlled application durable, silent access to the victim's data without stealing a password or re-prompting for MFA. The alert classifies the application owner as Microsoft first-party, in-tenant or external to help prioritize review.
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.
Detection requirements
- Platform
- ContainersIaaSIdentity ProviderLinuxmacOSOffice SuiteSaaSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
Known benign triggers
- Onboarding of a sanctioned mail client, add-in, backup, archiving, CRM, calendar or SharePoint application that legitimately requires delegated access with a refresh token. Validate publisher verification, application ownership (Esql.app_owner_type) and whether the scopes align with an approved business use case, then add an exception for the reviewed application. Microsoft first-party developer tooling such as Graph Explorer or Microsoft Graph Command Line Tools may legitimately request mailbox or file scopes when used by IT staff. Restricting end-user consent to verified publishers and low-risk permissions reduces this residual set to unsanctioned applications only.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| github.com/AlteredSecurity/365-Stealer | 8from 2 sources |
| learn.microsoft.com/en-us/defender-cloud-apps/investigate-risky-oauth | 10from 2 sources |
| learn.microsoft.com/en-us/entra/architecture/security-operations-applications#end-user-consent | 13from 2 sources |
| learn.microsoft.com/en-us/entra/identity/enterprise-apps/manage-app-consent-policies | Only this detection cites it |
| learn.microsoft.com/en-us/security/operations/incident-response-playbook-app-consent | 3from 2 sources |
| www.microsoft.com/en-us/security/blog/2024/01/25/midnight-blizzard-guidance-for-responders-on-nation-state-attack/ | 12from 2 sources |
From the source
- At source
- Open at source
- Upstream identifier
- e907ca08-45f2-4f8b-9854-c66be0e985dd
- Tagged by the source as
- Data Source: AzureData Source: Microsoft Entra IDData Source: Microsoft Entra ID Audit LogsDomain: CloudDomain: IdentityPlatform: Entra IDProfile: BetaResources: Investigation GuideRule Type: ES|QLTactic: Credential AccessTactic: Initial AccessThreat: OAuth App ConsentUse Case: Identity and Access Audit
Licence
- Published under
- Elastic License 2.0Read the licence
- Attribution
- Required
Authorship
- Written by
- Published
- Oct 9, 2026
- Version
- 1