← All posts post

The Takeover That Skips the Password

OAuthOctober 2026 · 1 min read

Not every account takeover needs a password.

Microsoft describes an illicit consent grant attack like this: the attacker registers an app in Microsoft Entra ID that asks for access to things like email, contacts, or documents, then tricks a user into granting that app consent.

No credential theft. No failed logins. The user clicked "Accept" on what looked like a normal app prompt.

The ugly part: resetting the password and revoking sessions doesn't remove the consent grant itself. The app stays authorized until someone finds it and revokes it.

What I look at when OAuth is in play:

  • Apps the user consented to recently
  • Permissions that don't match the app's stated purpose, especially mail access
  • Publishers nobody can vouch for
  • Activity from the app after consent

If your compromise playbook stops at "reset password, revoke sessions," the grant is still sitting there.

Sources

  1. Microsoft Learn: Detect and remediate illicit consent grants
  2. Microsoft Learn: Protect against consent phishing