ConsentFix: OAuth Phishing That Bypasses MFA in Microsoft Entra ID
ID: 2636d81d-f670-5b69-ba22-0f11187068d9
STIX ID: report--2636d81d-f670-5b69-ba22-0f11187068d9
Feed Name: Mitiga
ConsentFix is a browser-based OAuth consent-phishing technique targeting Microsoft Entra ID that tricks users into exposing authorization codes (via copy-paste or drag-and-drop of localhost redirect URLs) which attackers redeem for access and refresh tokens, enabling programmatic access to Azure, Microsoft 365, and connected SaaS. The report outlines the attack flow, explains why pre-trusted first-party apps and native OAuth flows allow MFA and conditional access bypasses, discusses potential impact (account takeover, data exfiltration, lateral movement), and provides mitigations such as token protection, restricting first-party app access, continuous monitoring, session revocation, and user education.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
