In March, Microsoft's security team published a breakdown of attackers abusing OAuth apps — those "Sign in with Microsoft" permission screens — to route people to phishing pages and malware.
Here's the part that should get a managing partner's attention: your team has already clicked those screens.
A PDF tool. An e-signature add-in. A scheduling app. An AI notetaker somebody tried once before a client call. Each one asked to read mail, or files, or the calendar. Someone clicked Accept. And by default in Microsoft 365, most staff can approve that on their own — no admin involved, no ticket, no record anyone ever reads.
That's not a password problem, and it doesn't behave like one. Microsoft is blunt about it: resetting passwords or turning on MFA isn't effective against this, because the app is external to your organization. It isn't a person logging in. It's an outside service holding a key you already handed over. Someone has to go into the tenant and take the key back.
For a firm that runs its matters out of email and OneDrive, that's the difference between a bad afternoon and a phone call to a client about where their file went.
Two things worth an hour this month: pull the list of apps your tenant has consented to and actually read it, then turn off blanket self-service consent so the next one comes to you first.
Cheapest security work you'll do this quarter.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email