logo

New OAuth Attack Lets Hackers Bypass Microsoft Entra Authentication and Steal Keys

ID: f1832b1e-dc0a-5700-9915-cad3a954aa72

STIX ID: report--f1832b1e-dc0a-5700-9915-cad3a954aa72

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

ConsentFix is a newly reported OAuth 2.0-based attack that tricks users into exposing authorization codes from Microsoft Entra ID first-party apps (e.g., Azure CLI); attackers then redeem those codes to obtain access, ID, and refresh tokens, potentially bypassing Conditional Access and device compliance checks. The report documents forensic detection via correlated SessionId values between the victim’s interactive sign-in and the attacker’s non-interactive redemption, enumerates affected Microsoft first-party tools, and recommends mitigations such as explicit service principal assignment, Conditional Access restrictions, and enabling Microsoft Entra Token Protection (WAM).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.