Skip to content

Consent To Application

Azure

Consent To Application

service: Azure - Microsoft Entra ID
techniques:

Event

Records application consent; inspect the actual grants to distinguish delegated scopes from application permissions. Tenant-wide delegated admin consent removes the need for each user to consent to approved scopes. It does not convert delegated access into app-only access or create a signed-in session for every user.

Security Context

Illicit consent can enable application-token abuse (contextual T1528) or persistent permission manipulation (T1098). Legitimate onboarding uses the same event. Delegated access acts on behalf of an authenticated user and is bounded by the granted scopes, the user’s access, and applicable policies; this event is not proof of stolen tokens or data reads.

Log Source

Microsoft Entra directory audit logs with activityDisplayName: Consent to application and category: ApplicationManagement. Check result/resultReason and correlate stable object IDs. The sample uses Microsoft Graph directoryAudit-style JSON; Azure Monitor AuditLogs exports use different field names and casing.

Key Fields

FieldInvestigation value
targetResources[].modifiedPropertiesConsent flags and permission details where supplied; parse string-encoded values.
targetResources[].idClient service principal; resolve resource, scope, consentType, and principalId from actual grants.

What to Investigate

  1. Confirm the recorded outcome and match the initiating identity, target, and timing to an approved change.
  2. Verify consent approval and the actor’s authority; Azure elevateAccess does not assign the Entra Global Administrator role.
  3. Inspect delegated oauth2PermissionGrants and application appRoleAssignments separately. AllPrincipals is tenant-wide consent, not a token for every user.
  4. Correlate user/workload sign-ins, token context where available, and resource audit evidence before claiming mailbox or file access.

Sample Event

Synthetic scenario. The sample illustrates tenant-wide admin consent for delegated Mail.Read, Files.Read.All, and User.Read.All. It does not demonstrate app-only permission, refresh-token issuance, or organization-wide unattended data access.

Exact field presence, target ordering, modified-property names, and payload serialization remain unverified against captured logs. Treat these examples as illustrations, not guaranteed schemas or complete change histories.

{
"id": "Directory_90000000-0000-4000-8000-000001101111_6E5D2_38492170",
"category": "ApplicationManagement",
"correlationId": "90000000-0000-4000-8000-000001101111",
"result": "success",
"resultReason": "",
"activityDisplayName": "Consent to application",
"activityDateTime": "2026-04-15T19:24:17.0381728Z",
"loggedByService": "Core Directory",
"operationType": "Assign",
"initiatedBy": {
"app": null,
"user": {
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"userPrincipalName": "draco@fantasticlogs.cloud",
"ipAddress": "203.0.113.66"
}
},
"targetResources": [
{
"id": "40000000-0000-4000-8000-001010011011",
"displayName": "BoggartImpersonator",
"type": "ServicePrincipal",
"userPrincipalName": null,
"groupType": null,
"modifiedProperties": [
{
"displayName": "ConsentAction.Permissions",
"oldValue": "[]",
"newValue": "[\"Scope: Mail.Read, Files.Read.All, User.Read.All\"]"
},
{
"displayName": "ConsentContext.IsAdminConsent",
"oldValue": "[]",
"newValue": "[\"True\"]"
},
{
"displayName": "ConsentContext.OnBehalfOfAll",
"oldValue": "[]",
"newValue": "[\"True\"]"
},
{
"displayName": "ConsentContext.Tags",
"oldValue": "[]",
"newValue": "[\"WindowsAzureActiveDirectoryIntegratedApp\"]"
},
{
"displayName": "TargetId.ServicePrincipalNames",
"oldValue": "[]",
"newValue": "[\"40000000-0000-4000-8000-001010011010\"]"
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"ConsentAction.Permissions, ConsentContext.IsAdminConsent, ConsentContext.OnBehalfOfAll, ConsentContext.Tags, TargetId.ServicePrincipalNames\""
}
]
}
],
"additionalDetails": [
{
"key": "User-Agent",
"value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
}
]
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation Credential Access

Techniques:
  • T1528 — Steal Application Access Token — Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.