Microsoft 365How-To & HardeningRetrospectives

How to Detect and Remove Malicious OAuth Apps in Microsoft 365

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.

Malicious OAuth apps can read mail and files without a password. Here is how to find and remove them in Microsoft 365.

Step 1: List apps with risky permissions

In the Entra admin center, review Enterprise applications and filter for apps with delegated or application permissions such as:

  • Mail.Read, Mail.ReadWrite, Mail.Send
  • Files.Read.All, Files.ReadWrite.All, Sites.Read.All
  • Contacts.Read, MailboxSettings.ReadWrite
  • offline_access combined with any of the above

Defender for Cloud Apps app governance or OAuth apps pages show permission levels, publisher status and usage in one view.

Step 2: Identify suspicious characteristics

  • Unverified publisher.
  • Recently created and consented to by many users.
  • Generic or misleading names ("Document Viewer," "Security Update").
  • Reply URLs on unusual domains.
  • Low community use (app governance shows rarity).

Step 3: Investigate

Check audit logs for consent events and data access by the app's service principal.

Step 4: Remove

For malicious apps:

  1. Disable the service principal (set Enabled for users to sign-in to No).
  2. Revoke all delegated permission grants and app role assignments.
  3. Delete the enterprise application after evidence is preserved.
  4. Revoke sessions for affected users.

Step 5: Prevent recurrence

Restrict user consent and enable the admin consent workflow.

Verify

Repeat the review quarterly and alert on new high-risk consent grants.

remove malicious oauth appsConsent phishing2020

More on this story