CIO Brief: The Phishing Attack MFA Can't Stop
Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.
The short version: In 2020, attackers began tricking employees into clicking "Accept" on a Microsoft permission screen for a fake app. The employee signs in normally — including multi-factor authentication — and the app quietly gains ongoing access to their email and files.
Why multi-factor authentication doesn't help here
Multi-factor authentication proves the user is who they say they are. In consent phishing, the real user signs in and approves the access themselves. The attacker never needs the password. Changing the password afterwards doesn't remove the app.
The business impact
- Silent data theft from mailboxes and files.
- Business email compromise, if the app can send mail as the user.
- Long-lasting access that standard incident response steps miss.
Questions to ask your team
- Can our employees approve apps that read their email or files without IT review?
- How many such apps are connected today?
- Would we notice if several employees approved the same unknown app in one day?
- Does our incident response process include removing malicious apps, not just resetting passwords?
What good looks like
Employees can approve only low-risk apps from verified publishers. Everything else goes through a quick admin review. High-access apps are reviewed regularly and monitored.
The decision
Ask your team to change user consent settings to the recommended restrictive option and turn on the admin approval workflow. It is a configuration change, not a project.
- Illicit Consent Grant Phishing (July 2020): Attackers Stop Stealing Passwords Incident Teardowns
- How to Detect and Remove Malicious OAuth Apps in Microsoft 365 How-To & Hardening
- Detecting Illicit Consent Grant: Defender XDR and Sentinel Hunting Queries Detection & Response