Microsoft Graph API and Permission Abuse: Illicit Consent, Application Roles, and OAuth Attacks
A comprehensive map of the attack surface on the OAuth permission model of Microsoft Graph API: illicit consent grant (T1528), service principal credential addition (T1098.001), application role escalation chains (T1098.003), and high-risk permission abuse. For each technique, Entra ID audit signals, KQL/Sigma, and hardening controls are provided.
Swipe or use the arrows to move between sections
Zafiyet (Vulnerability)
Tehdit bağlamı, zafiyet ve istismar senaryosu
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
Request the offline tool →Prevention & Hardening
Savunma teknolojileri, policy ve sertleştirme
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
Request the offline tool →Detection
Davranış, loglama ve detection kuralları
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
Request the offline tool →Mail.Read and Files.ReadWrite.All should be revoked. A common mistake: failing to monitor the active permissions of consented applications afterward (MITRE ATT&CK T1528).