In an illicit consent grant attack, threat actors register a malicious application to request access to sensitive organizational data. Mostly they trick users through phishing attempts or compromised websites to grant consent to that malicious app. This allows that app to access the organization's data without needing further authentication.
As password resets and MFA can’t prevent this type of attack, it’s important to review app consent grants to detect and stop unauthorized access.
- Analyze for indicators of compromise (IOC): Leverage the consent grant audit report to find all applications with admin consent grant. If you find multiple instances of the same application, it may indicate potential unauthorized consent grants.
- Review permissions granted to apps: Now, examine the impacted apps and its users, along with their permissions. To do that, use the following cmdlets to get all user and admin consent grant for the application.
Connect-MgGraph -Scopes "Application.Read.All", "DelegatedPermissionGrant.Read.All"
Get-MgServicePrincipal -Filter "DisplayName eq '<AppDisplayName>'" | ForEach-Object
{ Get-MgServicePrincipalOauth2PermissionGrant -ServicePrincipalId $_.Id } | Format-Table -Wrap -AutoSize
Note: Before executing the cmdlet above, replace <AppDisplayName> with the display name of the application for which you want to check consent grants.
Here, check the ConsentType to determine whether the permissions are admin consented, or user consented. The consent type ‘AllPrincipals’ indicates admin consent, while ‘Principal’ indicates user consent.
Handy Tip: After finding app consented with any high-privileged or unnecessary permissions, use the same consent grant audit report to see when the app had access. This will help you assess the full extent of the attack.
If you confirmed the attack, you could follow the steps below to remediate illicit consent grant attacks.
- In the Microsoft Entra portal, navigate to Identity » Users » All users » Select the user » Applications » Choose the illicit application » Remove.
- To revoke OAuth consent grant for user, you can use the PowerShell cmdlet below. Replace ID with the OAuth2 permission grant ID of the app obtained from the app consent investigation.
Connect-MgGraph -Scopes "DelegatedPermissionGrant.ReadWrite.All"
Remove-MgOauth2PermissionGrant -OAuth2PermissionGrantId <ID>
Further Consideration: Block sign-in for the affected user account to restrict app access, and disable user consent to mandate the admin approval for granting app access.