Entra ID OAuth Consent Can Grant ChatGPT Access to Emails
ID: 7b1cc49c-4376-588c-8092-33cf79eeeb55
STIX ID: report--7b1cc49c-4376-588c-8092-33cf79eeeb55
Feed Name: HackRead
Red Canary research describes an OAuth consent abuse case where a user at Contoso granted a ChatGPT app Mail.Read permission, enabling persistent background access via a Service Principal and token (App ID e0476654-c1d5-430b-ab80-70cbd947616a; Tenant ID 747930ee-9a33-43c0-9d5d-470b3fb855e7; user [email protected]; IP 3.89.177.26). The report explains how non-admin consent can bypass MFA, how to detect such cases by auditing "Add service principal" and "Consent to application" events, and advises removing consent grants to revoke access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
