Web Hack List

Collected research

Consent & Compromise: Abusing Entra OAuth for Fun and Access to Internal Microsoft Applications

Analyzes Microsoft Entra OAuth consent and first-party application behavior to obtain access to internal Microsoft services. The research combines delegated permissions, token exchanges, and trust in Microsoft-owned clients into practical cross-application compromise paths.

Record

Researcher
Vaisha Bernard and @eyesecurity_
Published by
Eye Research
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Vaisha Bernard and @eyesecurity_, first published at the original source. Preserved copies are kept so the citation survives its host.