logo

The “Fix” is a Trap: ConsentFix Phishing Bypasses MFA via Azure CLI

ID: 683e6300-6d46-5091-815a-f30a42c16a7c

STIX ID: report--683e6300-6d46-5091-815a-f30a42c16a7c

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-02

Date Updated: 2026-04-23

Author: Ddos

...
...

ConsentFix (AuthCodeFix) is a phishing technique that abuses the OAuth2 authorization-code flow for legitimate Microsoft first-party apps by redirecting victims to a localhost URL and instructing them to paste the URL (which contains the authorization code) into a phishing site; attackers then exchange that code for access tokens to bypass MFA and Conditional Access. The attack is difficult to block without impacting developer tools, but defenders can hunt for it by correlating the victim’s initial sign-in with a subsequent token exchange showing the same session ID from disparate IPs/locations in AADNonInteractiveUserSignInLogs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.