For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure application consent

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

AzureAD Audit Log

Detection Modules

Identity Threat Module, SaaS Threat Detection

ATT&CK Tactic

Initial Access (TA0001), Credential Access (TA0006)

ATT&CK Technique

Phishing (T1566), Phishing: Spearphishing Link (T1566.002), Steal Application Access Token (T1528), Trusted Relationship (T1199)

Severity

Informational

Description

An identity consented permissions to an application.

Attacker's Goals

Get access to credentials, data or an organization via applications with sufficient permissions.

Investigative actions

  • Follow further actions by the consenting user.

  • Check for new resource creations by the new user.

  • Check how the consenting user got to the application.

  • Verify the application creators.

  • Check what permissions the application requested.

  • Check for possible phishing in the organization.

Variations

Was this helpful?