Best Detection of 2026 Series – ConsentFix Malicious OAuth Device-Code Phishing

Detects instances where end users grant high-risk delegated permissions (e.g., Mail.Read, Files.ReadWrite.All) to applications via OAuth consent flows outside of standard administrator approval processes. This behavior is indicative of device-code phishing or consent phishing campaigns designed to gain unauthorized access to user data.