Not every account takeover needs a password.
Microsoft describes an illicit consent grant attack like this: the attacker registers an app in Microsoft Entra ID that asks for access to things like email, contacts, or documents, then tricks a user into granting that app consent.
No credential theft. No failed logins. The user clicked "Accept" on what looked like a normal app prompt.
The ugly part: resetting the password and revoking sessions doesn't remove the consent grant itself. The app stays authorized until someone finds it and revokes it.
What I look at when OAuth is in play:
- Apps the user consented to recently
- Permissions that don't match the app's stated purpose, especially mail access
- Publishers nobody can vouch for
- Activity from the app after consent
If your compromise playbook stops at "reset password, revoke sessions," the grant is still sitting there.