Hacking Endpoint to Identity (Microsoft 365): "ConsentFix"

Hacking Endpoint to Identity (Microsoft 365): "ConsentFix"

🎙 John Hammond 👥 2.2M 📅 December 13, 2025 ⏱ 19 min 👁 33K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OAuth consentClickFixAzure CLIidentity takeoverphishing

Summary

In this video, John Hammond analyzes a new phishing technique dubbed ‘ConsentFix’ that combines ClickFix social engineering with OAuth consent phishing to achieve account takeover in Microsoft 365 environments. The attack begins when a victim visits a compromised or malicious website, where a fake CAPTCHA prompts them to enter their email address. The attacker then opens a legitimate Microsoft login popup, pre-configured with the client ID of the trusted first-party Azure CLI application. If the victim is already logged in, they simply click ‘Sign in’ and are redirected to a localhost URL containing an authorization code. The attacker instructs the victim to copy and paste or drag and drop this URL back into the phishing page, thereby capturing the code. The attacker then exchanges this code for access and refresh tokens, gaining persistent access to the victim’s Microsoft 365 tenant, including email, Teams, and OneDrive. Hammond highlights that this technique is particularly insidious because it uses a trusted Microsoft app, requires no admin consent, and leaves minimal forensic artifacts. He demonstrates a proof-of-concept and discusses the social engineering friction and potential improvements. The video concludes with a discussion of detection challenges and the need for awareness.

196 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into a novel and sophisticated attack vector that bridges endpoint compromise to cloud identity compromise. The presenter clearly explains the technical details, including the use of Azure CLI as a trusted first-party application, and demonstrates a proof-of-concept. The argumentation is solid, based on a recent security research report, and the presenter’s own experimentation. However, some parts are speculative, such as the discussion on forensic artifacts and detection methods, which are not fully explored.

Scientific Rigor, Source Quality, Title Accuracy

The video references the Push Security blog post on ConsentFix, which is a credible source. The presenter also mentions other sources like Hex-Rays, but these are sponsors. The title accurately reflects the content. The video is not a peer-reviewed study but rather an expert analysis and demonstration. The presenter does not provide a comprehensive review of all related research, but the information presented is accurate and well-explained.

160 words

Title / Content Match

The title accurately reflects the content, which focuses on a novel attack technique that bridges endpoint compromise to cloud identity compromise.

Quality & Reliability

8/10

The video is based on a recent security research write-up by Push Security, which is a reputable firm. The presenter demonstrates a proof-of-concept and provides technical details, but the content is largely an expert commentary and speculation rather than a peer-reviewed study.

Key Moments

Cited Sources

Concurring Sources

External References

Contribution & Novelties

The video provides a clear and accessible explanation of a novel phishing technique that leverages trusted first-party OAuth applications to compromise Microsoft 365 accounts. It bridges the gap between endpoint-focused ClickFix attacks and cloud identity compromise, highlighting the low barrier to entry and the difficulty of detection. The presenter’s proof-of-concept demonstration adds practical value.

Pour aller plus loin :

85 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical depth, indicating a well-rounded and accessible analysis.

Reliability 8/10

💬 No comments were provided for analysis.