How to Detect and Remove Malicious OAuth Apps in Microsoft 365
Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.
Malicious OAuth apps can read mail and files without a password. Here is how to find and remove them in Microsoft 365.
Step 1: List apps with risky permissions
In the Entra admin center, review Enterprise applications and filter for apps with delegated or application permissions such as:
Mail.Read,Mail.ReadWrite,Mail.SendFiles.Read.All,Files.ReadWrite.All,Sites.Read.AllContacts.Read,MailboxSettings.ReadWriteoffline_accesscombined with any of the above
Defender for Cloud Apps app governance or OAuth apps pages show permission levels, publisher status and usage in one view.
Step 2: Identify suspicious characteristics
- Unverified publisher.
- Recently created and consented to by many users.
- Generic or misleading names ("Document Viewer," "Security Update").
- Reply URLs on unusual domains.
- Low community use (app governance shows rarity).
Step 3: Investigate
Check audit logs for consent events and data access by the app's service principal.
Step 4: Remove
For malicious apps:
- Disable the service principal (set Enabled for users to sign-in to No).
- Revoke all delegated permission grants and app role assignments.
- Delete the enterprise application after evidence is preserved.
- Revoke sessions for affected users.
Step 5: Prevent recurrence
Restrict user consent and enable the admin consent workflow.
Verify
Repeat the review quarterly and alert on new high-risk consent grants.
- Illicit Consent Grant Phishing (July 2020): Attackers Stop Stealing Passwords Incident Teardowns
- Detecting Illicit Consent Grant: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: The Phishing Attack MFA Can't Stop CIO Briefings