Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› CoPhish 2025: How Copilot Studio Agents Can Wrap…
Breach analysis Incident: 20 Oct 2025

CoPhish 2025: How Copilot Studio Agents Can Wrap OAuth Consent Phishing in a Trusted Microsoft Domain

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 7 min read
On this page

In October 2025, Datadog Security Labs described CoPhish, a way to use Microsoft Copilot Studio agents as a convincing wrapper for OAuth consent phishing. Copilot Studio lets users build chatbots, called agents, and share them through a "demo website" hosted on copilotstudio.microsoft.com. Datadog showed that an agent's built-in "Login" button can be configured to send a user to any URL, including an OAuth consent prompt for an attacker's application. If the user consents, the resulting token can be sent automatically by the agent's own workflow to a server the attacker controls, and then used to read email, chats or calendars as that user, depending on the permissions granted. Because the page sits on a real Microsoft domain and looks like other Copilot services, it is easier to trust. Datadog said the technique works against users consenting to allowed permissions on internal applications, and against administrators who can consent to any permissions. Microsoft said it would address the issue in future product updates. No attacks using the technique were reported in these sources.

Key takeaways

  • Copilot Studio agents shared as demo websites run on copilotstudio.microsoft.com, so phishing pages built with them look legitimate.
  • An agent's "Login" button can redirect users to an attacker's OAuth consent prompt, and the agent can forward the resulting token to the attacker.
  • Default Entra ID consent policies still let users grant some email, chat and calendar permissions to internal apps, and let application administrators grant any delegated permission.
  • Microsoft told BleepingComputer it is "taking action to address it through future product updates."
  • The identity lesson: an OAuth grant is a new non-human identity acting as the user, so consent policies and application governance are the real control.

At a glance

OrganisationsMicrosoft (Copilot Studio, Entra ID); Datadog Security Labs (research)
WhenPublished by Datadog on 20 October 2025; reported from 25 October 2025
AttackerNone known. Technique documented by Datadog Security Labs
Entry pointA malicious Copilot Studio agent shared via its demo website, redirecting users to an OAuth consent prompt
Identities abusedOAuth access tokens granted to an attacker's application; application administrator roles that can consent to any permission
ImpactPossible theft of user tokens with email, chat, calendar or broader permissions; no confirmed victims
CategoryNHI, Agentic AI and AI agents. Incident class: vulnerability found by researchers (vulnerability, no confirmed breach)

What happened

Datadog researcher Katie Knowles opened with a question: "Would you trust this website?" The page in question had a valid Microsoft URL and looked like a managed Copilot service, but it was a Copilot Studio agent. "In this post, we document a method by which a Copilot Studio agent's "Login" settings can redirect a user to any URL, including an OAuth consent attack," Datadog wrote. Its example also automated "exfiltration of the resulting token in Copilot Studio's topics," the workflows that drive agents, and noted that "an attacker could also configure a topic to take any action on behalf of a user with the token."

OAuth consent attacks trick a user into approving an application that requests access to their data. Microsoft has tightened defaults over the years; in July 2025 it made a stricter consent policy the default for Entra ID tenants, blocking user consent to SharePoint and OneDrive permissions. But Datadog showed two remaining scenarios. Users can still consent to permissions such as reading and sending email, chats and calendars for internal applications, which an attacker already inside a tenant can register. And "Users with the Cloud Application Administrator, Application Administrator, or a similar role can consent to any delegated Microsoft Graph permissions for any application," including applications from other tenants.

BleepingComputer reported that Microsoft said: "We've investigated this report and are taking action to address it through future product updates." Knowles told BleepingComputer that even after Microsoft's planned policy change, an external attacker could still "target an Application Administrator with an externally registered application." One visual clue, she said, is the Microsoft Power Platform icon on the agent page, which is easy to miss.

Timeline

DateEvent
July 2025Microsoft makes a stricter application consent policy the default for Entra ID tenants.
20 October 2025Datadog Security Labs publishes the CoPhish technique.
25 October 2025BleepingComputer reports the technique and Microsoft's response.
15 November 2025Paubox publishes a summary of the technique.

How it happened: the identity attack path

  1. Malicious app registered. The attacker creates an application requesting permissions to the victim's data.
  2. Agent built. A Copilot Studio agent's Login button is pointed at the app's consent prompt.
  3. Trusted link shared. The agent's demo website on a Microsoft domain is sent to the target.
  4. Consent granted. The victim approves the permissions, issuing a token to the attacker's app.
  5. Token exfiltrated. The agent's workflow forwards the token to the attacker, who can act as the user.

Impact

  • Potential: access to a user's email, chats and calendars, or to broader permissions if an application administrator consents.
  • Exploitation: none reported.
  • Vendor response: Microsoft plans product updates.

What this means for NHI governance

Every OAuth consent creates a non-human identity: an application holding a token that acts as the user. CoPhish does not break any control; it makes the consent step more convincing by hosting it on a trusted domain and automating the token theft with an AI agent's own workflow. That makes consent policy and application governance the controls that matter. If users cannot consent to risky permissions, and administrators' consent is reviewed, a convincing page achieves little.

AI agent platforms also deserve attention as a place where users can build and host content on trusted domains. Knowing who creates agents, what they can do and whom they are shared with is part of governing them. See our SaaS and OAuth App Governance Guide and Low-Code Agent Platforms Guide.

Recommendations

Frequently asked questions

What is CoPhish?

A technique documented by Datadog Security Labs that uses a Copilot Studio agent on a Microsoft domain to lead users to a malicious OAuth consent prompt and then forward the resulting token to the attacker.

Has CoPhish been used in real attacks?

No attacks were reported in the sources we reviewed. Microsoft said it would address the issue in future product updates.

How can organisations protect themselves?

Restrict user consent, limit application administrator roles and application registration, and monitor Copilot Studio agents and consent grants.

EchoLeak 2025 · Palo Alto Networks Salesforce Data Theft 2025 · SaaS and OAuth App Governance Guide · Low-Code Agent Platforms Guide · Enterprise AI Copilot Security Guide

How NHI Mgmt Group can help

OAuth grants and AI agents are multiplying faster than most teams can track. We help teams tighten consent policies, govern agent platforms and review which applications act on users' behalf. See our NHI and AI agent security training.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org