OAuth Consent Phishing

What Is the "Allow This App" Screen?

When you connect a third-party tool to Microsoft 365 or Google Workspace — for example, linking a church management system to your calendar, or connecting a scheduling app to your email — Microsoft or Google shows you a consent screen. This screen asks: "Do you want to give this app access to your account?"

OAuth consent phishing works by tricking staff into clicking Allow on a consent screen for an app the attacker controls. No password is stolen. No fake website is involved. The real Microsoft or Google page does the work, and the attacker's app receives long-lived access to email, files, and calendar.

login.microsoftonline.com
CH

Church Helper Pro

Publisher: Unknown

Church Helper Pro is requesting permission to:

  • Read your email
  • Send email on your behalf
  • Read and write your files
  • Access your contacts
  • Maintain access after you sign out

Accepting this will grant the above permissions to Church Helper Pro.

How to Read a Permissions Screen

Before clicking Allow or Accept on any consent screen, check these four things:

1. Did you request this?

If you did not start an integration — nobody walked you through connecting this app, you did not click a button inside a known tool — do not proceed. Unexpected consent links are a no.

2. Who is the publisher?

Look for a verified publisher badge (a checkmark next to a company name). "Unknown" or "unverified" means the app has not been reviewed by Microsoft. Legitimate business apps your church uses are nearly always verified.

3. What permissions are requested?

Read your email is different from read and write your files. "Maintain access after you sign out" means the token does not expire when you log off. Ask: does this app actually need all of these?

4. Does the app name match what you expect?

Attackers use names like "Office365 Security Update," "Teams File Sync," or lookalikes of real tools — "Zoom Helper," "DocuSign Connector." Compare carefully to the actual name of the product.

Church-Specific Consent Phishing Scenarios

Permissions That Should Raise Questions

These permission descriptions often appear on consent screens in plain English. Seeing any of these in a consent dialog for an unexpected app is a reason to pause:

Read your email

Gives the app access to every message in your inbox, including password resets for other accounts.

Send email on your behalf

Lets the app send email that appears to come from you — for phishing other staff or impersonating leadership.

Read and write files

Downloads or modifies everything in OneDrive or SharePoint, including donor lists and financial documents.

Maintain access after you sign out

The token does not expire when you log off. Access continues indefinitely unless an admin revokes it.

Sign in and read user profile

On its own this is low-risk, but combined with other permissions it allows full account enumeration.

Read your contacts

Exports your entire contact list — including member and donor information.

Staff and Admin Rules for Consent

Staff rule: Never click Allow on a consent screen you did not expect. If you did not go looking for an integration today, do not authorize one. Close the window and ask your IT contact.

Admin rule: Restrict or disable user consent in Microsoft 365 / Entra ID so that no staff member can authorize an app without an admin approving it first. This is covered in the Admin Defenses section.

When in doubt: A legitimate app integration can wait. Attackers create urgency. Real tools do not expire if you take ten minutes to verify with your admin.