OAuth Token Hijacking Bypasses MFA in Microsoft 365 Attacks
ConsentFix and ClickFix represent a new generation of social engineering attacks that exploit OAuth consent flows and user-executed commands to steal session tokens, effectively rendering MFA irrelevant once a token is surrendered. The root problem is that users are manipulated into voluntarily granting access — through drag-and-drop UI tricks or fake browser prompts — meaning no credential is ever stolen in the traditional sense. Organizations relying solely on MFA and standard security awareness training have a dangerous blind spot here, as these attacks operate entirely within legitimate authentication flows. The open sharing of detailed attack blueprints on cybercrime forums means threat actor skill barriers are extremely low, dramatically increasing the likelihood of widespread exploitation.
Tactical Insight
Immediate actions
- Audit and restrict third-party OAuth application consent permissions to prevent users from granting access to unverified apps via Azure AD/Entra ID admin controls.
- Enable Conditional Access policies that enforce device compliance and restrict token issuance to trusted, managed devices only.
- Alert users specifically about OAuth drag-and-drop and ClickFix-style prompt attacks through targeted, scenario-based security communications.
Long-term improvements
- Implement Continuous Access Evaluation (CAE) and short-lived token lifetimes to limit the window of opportunity for stolen session tokens.
- Enforce a zero-trust application consent model by requiring admin approval for all OAuth app registrations and third-party integrations.
- Regularly review and revoke orphaned or excessive OAuth token grants across all Microsoft 365 tenants using automated tooling.
Detection measures
- Monitor Microsoft Entra ID sign-in logs for anomalous OAuth consent grants, especially those originating from localhost callback URIs.
- Set up alerts for high-risk sign-in events and unusual application permission grants using Microsoft Defender for Cloud Apps or a SIEM.
- Conduct periodic red team exercises that simulate ClickFix and ConsentFix techniques to validate detection and response capabilities.