Name:Azure AD User Consent Blocked for Risky Application id:06b8ec9a-d3b5-4882-8f16-04b4d10f5eab version:12 date:None author:Mauricio Velazco, Splunk status:production type:TTP Description:The following analytic detects instances where Azure AD has blocked a user's attempt to grant consent to a risky or potentially malicious application.
This detection leverages Azure AD audit logs, focusing on user consent actions and system-driven blocks.
Monitoring these blocked consent attempts is crucial as it highlights potential threats early on, indicating that a user might be targeted or that malicious applications are attempting to infiltrate the organization.
If confirmed malicious, this activity suggests that Azure's security measures successfully prevented a harmful application from accessing organizational data, warranting immediate investigation to understand the context and take preventive measures. Data_source:
-Azure Active Directory Consent to application
search:`azure_monitor_aad` operationName="Consent to application" properties.result=failure