{"id":10811,"date":"2026-02-20T10:03:44","date_gmt":"2026-02-20T10:03:44","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/20\/hackers-using-oauth-apps-in-microsoft-entra-id-to-establish-persistence\/"},"modified":"2026-02-20T10:03:44","modified_gmt":"2026-02-20T10:03:44","slug":"hackers-using-oauth-apps-in-microsoft-entra-id-to-establish-persistence","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/20\/hackers-using-oauth-apps-in-microsoft-entra-id-to-establish-persistence\/","title":{"rendered":"Hackers Using OAuth Apps in Microsoft Entra ID to Establish Persistence"},"content":{"rendered":"<p>    Hackers Using OAuth Apps in Microsoft Entra ID to Establish Persistence<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Hackers are increasingly abusing <a href=\"https:\/\/cybersecuritynews.com\/new-oauth-based-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">OAuth applications in Microsoft Entra ID <\/a>to gain\u00a0persistent\u00a0access, blending in as normal \u201cbusiness integrations\u201d while keeping access even after defenders reset passwords.<\/p>\n<p>Recent Wiz research and incident reporting show attackers using fake OAuth apps, deceptive consent prompts, and redirect URLs to steal tokens and maintain long-term footholds in <a href=\"https:\/\/cybersecuritynews.com\/cisa-practices-secure-microsoft-365-cloud\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft 365 environments.<\/a><\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgqQo_DqAm04oYnP-gRurWbhVYqh1QDKV8R6iS6FsrF8sf9mSoYJrrCaKxF5P-uLpyiXK4PzO3rl699paLUVkSyah5dQM-yJfFIgJeu-xOHq1ijR0b9eEux4vQdWUtA_ta5JZOEuIIPtjy3J9UY0jATDOrp86sc3HIdOMNqxV5dNybeS4ySR0FcYlTINXw\/s1600\/Screenshot%25202026-02-19%2520193000%2520%25281%2529.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">proactive detection pipeline that flags emerging malicious OAuth apps across dozens of organizations (source: wiz)<\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading\" id=\"h-how-the-persistence-works\"><strong>How the persistence works<\/strong><\/h2>\n<p>In <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploiting-legacy-protocols-in-microsoft-entra-id\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Entra ID<\/a>, an app registration creates an application object in the app\u2019s \u201chome\u201d tenant. That application object acts as a blueprint for service principals created in other tenants where the app is used.<\/p>\n<p>A service principal is the local identity for the app in a tenant and defines what the app can do in that tenant, including which resources it can access once permissions are granted through registration or consent.\u200b<\/p>\n<p>Attackers exploit this model by convincing a user (or admin) to grant consent to a malicious or attacker-controlled OAuth app, which can establish an integration that functions like an always-on access path.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiE13jZT8HVDYrJEK8PDjUlEv2dq984FfUOTcrywfgedfEt6RAe6ht9OUVUem59uVTcLbybuwVJLkW9hDVX1Gx4Pa628OVJLmxDK-463t3KegcNJciRyq33u6skRLIARkYzKOZPFdGoco1g9LdZQgoTXMMKT5Oevp3zG3ZNdb5yCox1pz-Gl91nshixZUA\/s1600\/Screenshot%25202026-02-19%2520192924%2520%25281%2529.webp?ssl=1\" alt=\"Single global App ID for Teams unique Service Principal ID per company( source : .wiz)\"><figcaption class=\"wp-element-caption\">Single global App ID for Teams, unique Service Principal ID per company (source: wiz)<\/figcaption><\/figure>\n<p>MITRE notes adversaries can use <a href=\"https:\/\/cybersecuritynews.com\/microsoft-defender-xdr-expanded\/\" target=\"_blank\" rel=\"noreferrer noopener\">OAuth app integrations for persistence<\/a>, including by granting consent from a high-privileged account to maintain access even if they later lose that account.<\/p>\n<p>In some cases, these integrations can remain valid even after the original consenting user is disabled, and they may also help bypass MFA via application access tokens.<\/p>\n<p><a href=\"https:\/\/www.wiz.io\/blog\/detecting-malicious-oauth-applications\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Wiz recently described real-world tricks<\/a> that make a consent screen look legitimate. However, the app name uses a trick such as starting with a zero instead of the letter \u201cO.\u201d<\/p>\n<p>Introduced a detection pipeline called \u201cOAuth Apps Scout\u201d to surface emerging malicious OAuth applications.\u200b Threat reporting from Proofpoint tied fake Microsoft OAuth applications to campaigns observed in early 2025.<\/p>\n<p>Impersonated apps <a href=\"https:\/\/cybersecuritynews.com\/coldfusion-servers-under-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">(including Adobe and DocuSign themes<\/a>) redirected victims into <a href=\"https:\/\/cybersecuritynews.com\/yono-sbi-banking-app-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">attacker-in-the-middle<\/a> phishing flows using kits such as Tycoon.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgalBE9zIB5MXTEkCG3k9E_WNqONtdU_WDtY-UA75ghcQdC1ZPT1HCNb0BXcG4Rm5XryfIbUwT4QjXitIyJ2J9G-FZMk-2qmw8z2CmDntGJEMjkB7MloquJcTLSodRla_3X_no8na0zdOloQA1RYvoAJnjRvKYMcfsg18O33twBjVnIvfPVeED_DODwN8s\/s1600\/Screenshot%25202026-02-19%2520192845%2520%25281%2529.webp?ssl=1\" alt=\"The attack enticed users to approve OAuth consent for fake document-sharing apps( source : wiz)\"><figcaption class=\"wp-element-caption\">The attack enticed users to approve OAuth consent for fake document-sharing apps (source: wiz)<\/figcaption><\/figure>\n<\/div>\n<p>Proofpoint reported attempted account compromises affecting nearly 3,000 user accounts across more than 900 Microsoft 365 environments in 2025, with a confirmed success rate exceeding 50%.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-defensive-steps\"><strong>Defensive steps<\/strong><\/h2>\n<p>Microsoft\u2019s consent model allows admins to decide whether user consent is required and to enforce conditions that require administrator review and approval.<\/p>\n<p>Enabling an admin consent workflow can force \u201capproval required\u201d prompts when users aren\u2019t allowed to consent, <a href=\"https:\/\/cybersecuritynews.com\/what-is-authorization\/\" target=\"_blank\" rel=\"noreferrer noopener\">shifting risky app authorization decisions<\/a> to designated reviewers.\u200b<\/p>\n<p>Operationally, defenders should treat OAuth apps and service principals as inventory that must be continuously reviewed.<\/p>\n<p>With special scrutiny for new or low-prevalence apps, unusual redirect\/reply URLs, and high-impact permissions that don\u2019t match an app\u2019s stated purpose.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/microsoft-entra-id-for-persistence\/\">Hackers Using OAuth Apps in Microsoft Entra ID to Establish Persistence<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/microsoft-entra-id-for-persistence\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Using OAuth Apps in Microsoft Entra ID to Establish Persistence Hackers are increasingly abusing OAuth applications in Microsoft Entra ID to gain\u00a0persistent\u00a0access, blending in as normal \u201cbusiness integrations\u201d while keeping access even after defenders reset passwords. Recent Wiz research and incident reporting show attackers using fake OAuth apps, deceptive consent prompts, and redirect URLs [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,158],"tags":[130],"class_list":["post-10811","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-microsoft","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10811"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10811"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10811\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10811"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10811"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10811"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}