Back to all lessons
Awareness Lessons
3 weeks ago

MFA Is Not Enough: OAuth Consent Abuse Bypasses Authentication Controls

OAuth consent abuse exploits the trust model of delegated authorization, allowing attackers to trick users into granting malicious applications broad access to their data and accounts — entirely bypassing MFA, which only validates identity at login, not ongoing authorization. Once a user grants consent to a malicious OAuth app, the attacker receives persistent tokens that operate independently of the authentication session, meaning MFA provides no protection after the initial grant. This matters because many organizations falsely assume MFA is a comprehensive access control solution, leaving OAuth scopes ungoverned and token issuance unmonitored. Without strict OAuth governance, even well-secured identities can become a backdoor into sensitive resources.

Tactical Insight

Immediate actions

  • Audit all existing OAuth app consents across your environment and revoke any unauthorized or overly permissive grants immediately.
  • Restrict user ability to consent to third-party OAuth applications and require administrator approval for all new app registrations.
  • Enforce least-privilege OAuth scopes by denying requests for broad permissions (e.g., mail.read, files.readwrite.all) unless explicitly justified.

Long-term improvements

  • Implement a formal OAuth application governance policy that includes periodic reviews, scope justification requirements, and sunset procedures for unused tokens.
  • Integrate OAuth consent events into your SIEM to establish baseline behavior and detect anomalous third-party application access patterns.
  • Adopt a Zero Trust posture for delegated access by requiring continuous validation of OAuth token usage, not just point-in-time authentication.

Detection measures

  • Monitor for OAuth tokens with unusually broad scopes or tokens that access resources inconsistent with the granting user's role.
  • Set up alerts for bulk consent grants, consent grants from high-privilege accounts, or apps registered outside your approved vendor list.
  • Establish automated token revocation workflows that trigger upon detection of suspicious activity or upon user account compromise.