Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Using OAuth Apps in Microsoft Entra ID to Establish Persistence

Recent findings highlight the increasing abuse of OAuth applications within Microsoft Entra ID by malicious actors to establish persistent access. These applications are disguised as legitimate business integrations, allowing unauthorized access even…

Recent findings highlight the increasing abuse of OAuth applications within Microsoft Entra ID by malicious actors to establish persistent access. These applications are disguised as legitimate business integrations, allowing unauthorized access even after password resets.

Research indicates that attackers are leveraging fake OAuth apps, misleading consent prompts, and redirect URLs to steal tokens and maintain long-term presence in Microsoft 365 environments. This technique involves creating an application object in the app’s “home” tenant, which serves as a blueprint for service principals in other tenants where the app is deployed.

A service principal acts as the app’s local identity in a tenant, defining its permissions and access to resources. Attackers exploit this model by tricking users or admins into granting consent to malicious OAuth apps, creating a persistent access pathway.

According to MITRE, adversaries can maintain access through OAuth app integrations by obtaining consent from high-privileged accounts. This access path remains viable even if the original consenting account is disabled, potentially bypassing multi-factor authentication (MFA) via application access tokens.

Recent findings highlight the increasing abuse of OAuth applications within Microsoft Entra ID by malicious actors to establish persistent access.
Vanessa Ray · Thehackingpost

Wiz has developed a detection pipeline named “OAuth Apps Scout” to identify emerging malicious OAuth applications. Recent threat reporting linked fake Microsoft OAuth applications to attacks conducted in early 2025, where impersonated apps led victims into phishing flows using kits like Tycoon.

Proofpoint reported that nearly 3,000 user accounts across more than 900 Microsoft 365 environments were targeted in 2025, with a confirmed compromise success rate exceeding 50%.

To mitigate these threats, Microsoft’s consent model allows administrators to enforce conditions requiring approval for app consent. Implementing an admin consent workflow can shift risky authorization decisions to designated reviewers. Organizations should treat OAuth apps and service principals as inventory, requiring continuous evaluation.

Advertisement

Special attention should be given to new or uncommon apps, unusual redirect URLs, and permissions that do not align with the app's stated purpose.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories