Azure application consent
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AzureAD Audit Log
Detection Modules
Identity Threat Module, SaaS Threat Detection
ATT&CK Tactic
Initial Access (TA0001), Credential Access (TA0006)
ATT&CK Technique
Phishing (T1566), Phishing: Spearphishing Link (T1566.002), Steal Application Access Token (T1528), Trusted Relationship (T1199)
Severity
Informational
Description
An identity consented permissions to an application.
Attacker's Goals
Get access to credentials, data or an organization via applications with sufficient permissions.
Investigative actions
Follow further actions by the consenting user.
Check for new resource creations by the new user.
Check how the consenting user got to the application.
Verify the application creators.
Check what permissions the application requested.
Check for possible phishing in the organization.
Variations
Was this helpful?
