Third-Party App OAuth Risks

Third-Party App OAuth Risks

Check what you gave permission to access.

What Is Third-Party App OAuth Risks?

OAuth connects a third-party app to your work account in one click, and the token it receives lasts until someone revokes it. Consent phishing works because nothing in the flow looks wrong: the screen is genuine and the domain belongs to your own identity provider. Only the requested scope gives it away. You will weigh a scheduling tool that asks for your email and files, audit the apps already connected to your account, revoke what you no longer use, and spot apps named to imitate IT.

What You'll Learn in Third-Party App OAuth Risks

Third-Party App OAuth Risks — Training Steps

  1. A Productivity Recommendation

    You've been feeling overwhelmed with calendar management and email follow-ups. Your colleague Marcus mentioned a tool that helped him stay organized.

  2. Marcus's Recommendation

    You receive an email from Marcus about the productivity tool he mentioned.

  3. Connecting the App

    The tool sounds exactly like what you need. Marcus is a trusted colleague who wouldn't recommend something harmful. You click the link to check out SmartSync Pro.

  4. Authorizing the App

    The SmartSync Pro page looks professional and promises useful features. To connect the app, you need to authorize it through your Meridian Workspace account.

  5. The OAuth Consent Screen

    You're redirected to your company's Meridian Workspace portal, which displays a consent screen asking you to authorize SmartSync Pro. The app is requesting access to your account. You need to review the permissions and click 'Allow' to connect the app.

  6. App Connected Successfully

    SmartSync Pro is now connected to your Meridian account. The confirmation screen shows that the app can now access your data. You close the window and continue with your day, satisfied that you'll now have better calendar management.

  7. Three Weeks Later

    Three weeks pass. You've been using SmartSync Pro for calendar reminders - though it doesn't seem as sophisticated as Marcus described. One morning, you receive an urgent email from IT Security.

  8. A Sinking Feeling

    Your heart sinks as you read the alert. The productivity tool you installed has been secretly harvesting your data. In financial services, this kind of data exposure could have serious regulatory consequences. You need to contact IT Security right away.

  9. What Went Wrong

    David from IT Security explained that SmartSync Pro wasn't a legitimate productivity tool - it was a data harvesting application designed to steal corporate information. But wait - Marcus recommended it. Alice realizes she should check if Marcus actually sent that email. She opens the original message to examine it more closely.

  10. Examining the Sender

    Looking at Marcus's original email again, Alice decides to verify if Marcus actually sent it.

Security Framework Coverage

MITRE ATT&CK

  • T1528 Steal Application Access Token
  • T1550.001 Use Alternate Authentication Material: Application Access Token

CIS Controls

  • CIS 15 Service Provider Management
  • CIS 6 Access Control Management

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • GV.SC Cybersecurity Supply Chain Risk Management
  • PR.AA Identity Management, Authentication, and Access Control