Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

OAuth Attacks in Entra ID Can Leverage ChatGPT to Compromise User Email Accounts

## OAuth Consent Abuse in Microsoft Entra ID

OAuth Consent Abuse in Microsoft Entra ID

Recent investigations highlight an increasing trend of abuse in Microsoft Entra ID through OAuth consent abuse. This technique allows attackers to gain access to corporate users' email accounts without requiring their passwords.

OAuth, or Open Authorization , is a protocol that allows applications to access user data with permission. In Entra ID, users are presented with a consent prompt detailing requested permissions when connecting a third-party app. Threat actors exploit this by creating or disguising malicious applications that request sensitive permissions such as Mail.Read.

A case study identified by Red Canary involved a user, TestUser@ContosoCorp.onmicrosoft.com, consenting to OAuth permissions for a third-party application that appeared to be ChatGPT. Although this instance involved the legitimate OpenAI-owned ChatGPT, the procedure mirrored previous real-world attacks. The event was traced to IP address 3.89.177.26 on December 2, 2025, at 20:22:16 UTC.

The primary concern is not limited to specific applications like ChatGPT but extends to any third-party application that can gain the Mail.Read permission through user consent. This capability allows the application to silently access all messages in the user's inbox. Entra ID's default settings permit non-admin users to consent to applications, potentially exposing sensitive data.

Recent investigations highlight an increasing trend of abuse in Microsoft Entra ID through OAuth consent abuse.
Aiden Sinclair · Thehackingpost

When users connect an application via phishing or other means, two audit log events occur: "Add service principal" and "Consent to application," sharing a CorrelationId for traceability. Red Canary’s detection strategy focuses on identifying non-admin consent grants linked to new third-party applications with commonly abused OAuth scopes, such as Mail.Read, Files.Read.All, Chat.Read, and Sites.Read.All.

Upon confirming a malicious consent grant, revoke the OAuth permission using the grant ID from the audit log and remove the service principal using its object ID via Microsoft Graph PowerShell commands . Microsoft offers three consent policy options for prevention:

Advertisement

Administrator approval for all consent requests. Restriction to verified publishers with low-risk permissions. Automatic application of current user consent guidelines.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories