Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 840

OAuth Consent Phishing

OAuth Consent Phishing とは何ですか?

OAuth Consent PhishingAn identity attack that abuses the OAuth consent flow: instead of stealing a password, the attacker tricks the victim into granting their malicious app standing permissions (mail.read, files.read.all) on the victim's tenant.


OAuth consent phishing — also called 'illicit consent grant' — bypasses MFA and password security entirely by abusing legitimate identity flows. The attacker registers a third-party application in a target identity provider (Microsoft Entra ID, Google Workspace, Okta, GitHub) with broad permission scopes such as Mail.Read, Files.Read.All, or repo. They then send the victim a real OAuth authorization URL hosted on the IdP's domain ('login.microsoftonline.com', 'accounts.google.com') — TLS-pinned, MFA-honored, and bearing the IdP's branding. The victim clicks 'Accept', the IdP issues the attacker a refresh token, and the attacker can read mail, exfiltrate files, and post on the victim's behalf for as long as the consent stands, with no further authentication challenge. This was the technique behind Pawn Storm/APT28's 2016–2017 campaigns and remained the top-trending Entra ID risk in 2024–2025. Defenses include tenant policies that require admin approval for third-party apps, allowlists of pre-approved publishers, periodic revocation reviews, and user training to inspect the displayed permissions and publisher before clicking accept.

  1. 01

    An attacker emails a victim a calendar invite that links to a Microsoft consent URL for an app named 'Calendar Helper' requesting `Mail.ReadWrite` and `Files.Read.All`; once granted, the attacker reads the user's mailbox over the Graph API.

  2. 02

    An Entra ID tenant policy blocks user consent to unverified publishers and requires global admin review for any scope beyond `User.Read`.

よくある質問

OAuth Consent Phishing とは何ですか?

An identity attack that abuses the OAuth consent flow: instead of stealing a password, the attacker tricks the victim into granting their malicious app standing permissions (mail.read, files.read.all) on the victim's tenant. サイバーセキュリティの 攻撃と脅威 カテゴリに属します。

OAuth Consent Phishing とはどういう意味ですか?

An identity attack that abuses the OAuth consent flow: instead of stealing a password, the attacker tricks the victim into granting their malicious app standing permissions (mail.read, files.read.all) on the victim's tenant.

OAuth Consent Phishing はどのように機能しますか?

OAuth consent phishing — also called 'illicit consent grant' — bypasses MFA and password security entirely by abusing legitimate identity flows. The attacker registers a third-party application in a target identity provider (Microsoft Entra ID, Google Workspace, Okta, GitHub) with broad permission scopes such as Mail.Read, Files.Read.All, or repo. They then send the victim a real OAuth authorization URL hosted on the IdP's domain ('login.microsoftonline.com', 'accounts.google.com') — TLS-pinned, MFA-honored, and bearing the IdP's branding. The victim clicks 'Accept', the IdP issues the attacker a refresh token, and the attacker can read mail, exfiltrate files, and post on the victim's behalf for as long as the consent stands, with no further authentication challenge. This was the technique behind Pawn Storm/APT28's 2016–2017 campaigns and remained the top-trending Entra ID risk in 2024–2025. Defenses include tenant policies that require admin approval for third-party apps, allowlists of pre-approved publishers, periodic revocation reviews, and user training to inspect the displayed permissions and publisher before clicking accept.

OAuth Consent Phishing からどのように防御しますか?

OAuth Consent Phishing に対する防御は通常、上記の定義で述べたとおり、技術的統制と運用上の実践を組み合わせます。

OAuth Consent Phishing の別名は何ですか?

一般的な別名: Illicit consent grant, Application consent attack。

関連用語

関連項目