logo

5-Minute Hunt: Detecting Risky Multi-Tenant Apps in Microsoft 365 by Lucie Cardiet

ID: e806f55b-746b-5870-b39e-f3a5e3add69b

STIX ID: report--e806f55b-746b-5870-b39e-f3a5e3add69b

Feed Name: Vectra AI Blog

Threat Score
65/100

Date Published: 2025-09-09

Date Updated: 2026-05-01

...
...

**Executive summary:** This brief hunt explains how misconfigured Microsoft 365 multi-tenant apps create a consent-based attack surface that attackers exploit via OAuth consent phishing and token authority abuse, outlines attacker behaviors and investigative signals, and provides a ready-to-run query to detect when an application's AvailableToOtherTenants property is set to true so SOC teams can identify and remediate unauthorized multi-tenant configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.