Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is an application-consent foothold?

An application-consent foothold is continuing access through permissions granted to an application. Because the application can call provider APIs without an ordinary interactive login each time, password reset may not remove that access.

Define the grant and its scope

Preserve the application's stable identifier, tenant and publisher information, permissions requested and granted, consenting identity, consent time, approval route, and credentials or certificates. Display names can be copied and should not be relied upon.

Determine whether an ordinary user, administrator or deployment process granted consent. The permission model decides whether access covers one account, several users or organisation-wide resources. Verify provider behaviour applicable at the relevant time.

Prove what the application did

Consent establishes authorised capability at the platform level, not use of every permission. API and audit records can show which mail, files, profiles or other resources were actually accessed.

Technical approval may have been obtained through deception and does not by itself prove informed intent. Preserve the surrounding messages and interface events where relevant. Record revocation and test whether application credentials, grants and sessions were all invalidated.

Key takeaway

Connect the application's stable identity, consent scope and API activity, and verify revocation independently of the user's password.

Reference: CIM-115Cyber Incidents & Offender Methods