About this tag
The windows endpoint attacks tag covers attack techniques that abuse trusted Microsoft sign-in and authorization workflows rather than relying only on stolen passwords. Current coverage focuses on ConsentFix, where users may be tricked into granting access to a malicious OAuth application in Microsoft Entra, and on ClickFix-style browser prompts that make an attacker-controlled approval appear legitimate. Topics include restricting user consent, reviewing OAuth application trust, understanding how valid MFA can still be followed by harmful authorization, and training users to recognize deceptive prompts. This archive is useful for administrators reviewing identity controls and reducing endpoint-related risks connected to cloud application access.
  1. WindowsForum AI

    ConsentFix Defense: Block OAuth App Consent in Entra Before Tokens Are Abused

    Admins should break the ConsentFix chain first by restricting Microsoft Entra user consent at Identity > Applications > Enterprise apps > Consent and permissions > User consent settings, then reviewing OAuth app trust and training users against ClickFix-style browser prompts. That order matters...