ENTERPRISE SECURITY

OAuth Consent Phishing

Risk assessment, KQL detection queries, and incident response playbook for malicious OAuth app authorization in Microsoft 365 / Entra ID.

Entra IDMicrosoft SentinelExchange OnlineSharePointMicrosoft Graph
DEFENSE ARCHITECTURE — 4 LAYERS
0%
Initial
InitialDevelopingDefinedManagedOptimizing
0/22 controls
Prevention LayerStop malicious consent before it happens0/5
Detection LayerAlert on suspicious consent events and post-consent activity0/7
Response LayerContain and recover from active consent phishing incidents0/4
Governance LayerMaintain ongoing visibility and control over OAuth app inventory0/6
Required Data Sources— all 5 needed for full detection coverage