heroui logo

Entra ID End-User Consent to Application with High-Risk Delegated Scopes

Elastic Detection Rules

View Source
Summary
Detects end-user (non-admin) consent to a Microsoft Entra ID application for high-risk delegated scopes, a common precursor to OAuth phishing and credential abuse. The rule inspects Entra ID audit logs for successful Consent to application events where IsAdminConsent is false and the granted permissions contain high-risk scope families (mail, mailbox_settings, contacts, files, sites, notes, teams_chat, sharepoint_spo, exchange_ews). It also accounts for the presence of offline_access, which yields a long-lived refresh token and enables durable, silent access. Derived fields categorize scopes into high- and low-risk families, classify the app_owner_type (microsoft, tenant, external), and indicate whether the service principal was provisioned by this consent. The alert logic triggers when there is a high-risk scope with offline_access, or when high-risk scopes appear (including SharePoint/Exchange Web Services), or when an external app presents multiple low-risk scopes with offline_access. The rule surfaces key indicators to aid triage, including target app, initiating user, source IP, the consent event correlation, and the exact scopes granted. It also maps the event to MITRE ATT&CK techniques (Phishing/T1566 and Steal Application Access Token/T1528) and provides remediation steps such as revoking tokens and blocking the app. The rule includes detailed false-positive guidance for sanctioned tools and Microsoft first-party utilities, and offers investigation steps to verify publisher, ownership, and scope alignment, plus follow-on activity checks (e.g., mailbox/file exfiltration, rule creation).
Categories
  • Cloud
  • Identity Management
Data Sources
  • Cloud Service
  • Application Log
ATT&CK Techniques
  • T1566
  • T1566.002
  • T1528
Created: 2026-10-02