logo

ConsentFix (a.k.a. AuthCodeFix): Detecting OAuth2 Authorization Code Phishing

ID: 1b417bd5-fcbe-5afa-a87d-3f107f44ff8b

STIX ID: report--1b417bd5-fcbe-5afa-a87d-3f107f44ff8b

Feed Name: NVISO Labs

Threat Score
70/100

Date Published: 2026-01-29

Date Updated: 2026-04-28

Author: Stamatis Chatzimangou

...
...

ConsentFix (AuthCodeFix) is an OAuth2 authorization-code phishing technique that social-engineers victims into providing localhost redirect URLs containing authorization codes; attackers then exchange those codes for access tokens to gain access to Microsoft accounts. The report explains the mechanics, lists vulnerable first-party Microsoft applications and their app IDs, gives step-by-step replication instructions (victim and adversary), provides a KQL detection/hunting query correlating interactive and non-interactive sign-ins, and recommends mitigations such as service principal user-assignment, Conditional Access restrictions, and token protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.