5-Minute Hunt: Detecting Risky Multi-Tenant Apps in Microsoft 365 by Lucie Cardiet
ID: e806f55b-746b-5870-b39e-f3a5e3add69b
STIX ID: report--e806f55b-746b-5870-b39e-f3a5e3add69b
Feed Name: Vectra AI Blog
Threat Score
**Executive summary:** This brief hunt explains how misconfigured Microsoft 365 multi-tenant apps create a consent-based attack surface that attackers exploit via OAuth consent phishing and token authority abuse, outlines attacker behaviors and investigative signals, and provides a ready-to-run query to detect when an application's AvailableToOtherTenants property is set to true so SOC teams can identify and remediate unauthorized multi-tenant configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
