Affected Systems

Microsoft 365 accounts across all organizations using OAuth authentication. Campaigns target users through social engineering to approve malicious OAuth consent prompts, bypassing MFA protections by stealing valid authentication tokens.

Exploitation Status

Active exploitation confirmed. ConsentFix and ClickFix are ongoing attack campaigns actively targeting Microsoft 365 users through fake OAuth authorization prompts and consent screens.

Business Impact

Attackers gain full access to compromised M365 accounts within seconds, bypassing MFA entirely. Once tokens are stolen, threat actors can access email, SharePoint, OneDrive, and other M365 services without triggering authentication alerts. High risk for data exfiltration, business email compromise (BEC), and lateral movement within tenant environments.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Review and audit all OAuth application consents in Azure AD/Entra ID admin center; revoke suspicious third-party app permissions immediately
  • Enable Conditional Access policies in Azure AD to restrict OAuth app consent to admin-approved applications only
  • Monitor Azure AD sign-in logs and audit logs for unusual OAuth consent grants, focusing on newly registered applications and consent events from unfamiliar sources
  • Implement user awareness training specifically on identifying fake OAuth prompts and verifying application publisher legitimacy before granting consent
  • Deploy Microsoft Defender for Cloud Apps (MCAS) OAuth app governance policies to detect and block risky OAuth applications automatically