Microsoft 365CIO BriefingsRetrospectives

CIO Brief: The Phishing Attack MFA Can't Stop

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.

The short version: In 2020, attackers began tricking employees into clicking "Accept" on a Microsoft permission screen for a fake app. The employee signs in normally — including multi-factor authentication — and the app quietly gains ongoing access to their email and files.

Why multi-factor authentication doesn't help here

Multi-factor authentication proves the user is who they say they are. In consent phishing, the real user signs in and approves the access themselves. The attacker never needs the password. Changing the password afterwards doesn't remove the app.

The business impact

  • Silent data theft from mailboxes and files.
  • Business email compromise, if the app can send mail as the user.
  • Long-lasting access that standard incident response steps miss.

Questions to ask your team

  • Can our employees approve apps that read their email or files without IT review?
  • How many such apps are connected today?
  • Would we notice if several employees approved the same unknown app in one day?
  • Does our incident response process include removing malicious apps, not just resetting passwords?

What good looks like

Employees can approve only low-risk apps from verified publishers. Everything else goes through a quick admin review. High-access apps are reviewed regularly and monitored.

The decision

Ask your team to change user consent settings to the recommended restrictive option and turn on the admin approval workflow. It is a configuration change, not a project.

consent phishing impactConsent phishing2020

More on this story