logo

Microsoft Entra ID OAuth Phishing and Detections

ID: 3f54c443-1e0b-5e97-bfed-321523c24cc2

STIX ID: report--3f54c443-1e0b-5e97-bfed-321523c24cc2

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2025-06-25

Date Updated: 2026-04-27

...
...

## Executive Summary This report analyzes OAuth phishing campaigns against Microsoft Entra ID (Azure AD), reproducing Volexity-observed techniques that abuse first‑party Microsoft apps and ROADtools to harvest tokens, register virtual devices, and mint Primary Refresh Tokens (PRTs) for persistent, stealthy access to Microsoft 365 resources; it documents two emulated scenarios (VSCode-based Graph access and Microsoft Authentication Broker-based device registration), provides telemetry and high-fidelity detection rules, and recommends log-correlation and SIEM detections to surface token abuse and device-registration driven compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.