Microsoft 365Detection & ResponseRetrospectives

Detecting Illicit Consent Grant: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.

Illicit consent grants give attackers persistent access to Microsoft 365 data. Detecting them quickly is essential because password resets don't remove them.

Signals worth watching

  • A user consenting to an app requesting mail or file permissions, especially from an unverified publisher.
  • Several users consenting to the same new app within a short period.
  • Consent events immediately after a user clicks a link in an email.
  • The app's service principal accessing many mailboxes or large volumes of data.
  • App governance alerts for unusual data access or suspicious app behavior.

Where the data lives

  • Entra ID audit logs: "Consent to application," "Add OAuth2PermissionGrant," "Add app role assignment to service principal."
  • Defender for Cloud Apps / app governance alerts.
  • Defender for Office 365: URL click data linking emails to consent pages.
  • Unified audit log: MailItemsAccessed and file access by the app.

A starting query

Multiple users consenting to the same app:

AuditLogs
| where OperationName == "Consent to application"
| extend App = tostring(TargetResources[0].displayName), AppId = tostring(TargetResources[0].id)
| summarize Users = dcount(tostring(InitiatedBy.user.userPrincipalName)), FirstSeen = min(TimeGenerated)
    by App, AppId
| where Users > 3

Response

  1. Disable the app and revoke grants.
  2. Identify all users who consented and review data accessed.
  3. Block the publisher or app ID tenant-wide.
  4. Notify users and reinforce training.
detect illicit consent grantConsent phishing2020

More on this story