Tag
medium
advisory
Azure AD Risk-Based Consent Disabled
2 rules 1 TTPThe analytic detects when the risk-based step-up consent security setting in Azure AD is disabled by monitoring Azure Active Directory logs for the 'Update authorization policy' operation and changes to the 'AllowUserConsentForRiskyApps' setting, potentially exposing organizations to OAuth phishing attacks.
Azure Active Directory
azure
oauth
consent
phishing
2r
1t
high
advisory
Azure AD OAuth Application Consent Granted by User
2 rules 2 TTPsDetection of Azure AD OAuth application consent granted by a user, potentially leading to unauthorized access and data compromise.
Azure AD
azure
oauth
consent
application
t1528
2r
2t