Third-Party App OAuth Risks
Check what you gave permission to access.
What Is Third-Party App OAuth Risks?
OAuth connects a third-party app to your work account in one click, and the token it receives lasts until someone revokes it. Consent phishing works because nothing in the flow looks wrong: the screen is genuine and the domain belongs to your own identity provider. Only the requested scope gives it away. You will weigh a scheduling tool that asks for your email and files, audit the apps already connected to your account, revoke what you no longer use, and spot apps named to imitate IT.
What You'll Learn in Third-Party App OAuth Risks
- Evaluate OAuth consent screens by comparing requested permissions against what an app legitimately needs to function
- Audit all third-party applications currently connected to your corporate accounts and identify those with excessive or unnecessary permissions
- Revoke OAuth tokens for unused, suspicious, or overly permissioned third-party applications
- Recognize consent phishing attacks where malicious apps disguise themselves as legitimate IT or security tools
- Apply your organization's app approval process before authorizing new third-party tools to access corporate data
Third-Party App OAuth Risks — Training Steps
-
A Productivity Recommendation
You've been feeling overwhelmed with calendar management and email follow-ups. Your colleague Marcus mentioned a tool that helped him stay organized.
-
Marcus's Recommendation
You receive an email from Marcus about the productivity tool he mentioned.
-
Connecting the App
The tool sounds exactly like what you need. Marcus is a trusted colleague who wouldn't recommend something harmful. You click the link to check out SmartSync Pro.
-
Authorizing the App
The SmartSync Pro page looks professional and promises useful features. To connect the app, you need to authorize it through your Meridian Workspace account.
-
The OAuth Consent Screen
You're redirected to your company's Meridian Workspace portal, which displays a consent screen asking you to authorize SmartSync Pro. The app is requesting access to your account. You need to review the permissions and click 'Allow' to connect the app.
-
App Connected Successfully
SmartSync Pro is now connected to your Meridian account. The confirmation screen shows that the app can now access your data. You close the window and continue with your day, satisfied that you'll now have better calendar management.
-
Three Weeks Later
Three weeks pass. You've been using SmartSync Pro for calendar reminders - though it doesn't seem as sophisticated as Marcus described. One morning, you receive an urgent email from IT Security.
-
A Sinking Feeling
Your heart sinks as you read the alert. The productivity tool you installed has been secretly harvesting your data. In financial services, this kind of data exposure could have serious regulatory consequences. You need to contact IT Security right away.
-
What Went Wrong
David from IT Security explained that SmartSync Pro wasn't a legitimate productivity tool - it was a data harvesting application designed to steal corporate information. But wait - Marcus recommended it. Alice realizes she should check if Marcus actually sent that email. She opens the original message to examine it more closely.
-
Examining the Sender
Looking at Marcus's original email again, Alice decides to verify if Marcus actually sent it.
Security Framework Coverage
MITRE ATT&CK
- T1528 Steal Application Access Token
- T1550.001 Use Alternate Authentication Material: Application Access Token
CIS Controls
- CIS 15 Service Provider Management
- CIS 6 Access Control Management
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
- GV.SC Cybersecurity Supply Chain Risk Management
- PR.AA Identity Management, Authentication, and Access Control