Join our Newsletter — 33% off our NHI Course
Authentication, Authorisation & Trust

Consent Injection

← Back to Glossary
By NHI Mgmt Group Updated October 7, 2026 Domain: Authentication, Authorisation & Trust

Consent injection is the abuse of OAuth or directory approval flows to grant an application access it should not have. In Entra ID contexts, it can turn a normal permission object into a durable trust decision that outlives the initial compromise.

Consent injection is an OAuth abuse pattern, not a password theft pattern. The attacker tries to get a user or tenant administrator to approve an application that then receives legitimate-looking access tokens, scopes, or directory permissions.

The important distinction is that the approval itself becomes the security event. Once granted, the application may inherit durable access that appears sanctioned by the platform, which makes the resulting trust harder to spot than a conventional credential compromise.

Consent injection matters because consent can function as delegated authority. If the user or admin approval is obtained under misleading conditions, the application may gain the same access that a legitimately approved app would receive, including access to mailboxes, files, profiles, or directory data.

In directory-centric environments, that approval can outlast the initial compromise and create a standing foothold until the grant is reviewed and revoked. NHIMG’s Identity Data Privacy and Consent Guide is useful here because it connects consent decisions with delegated access and identity-data handling, which is exactly where misuse becomes durable.

This is why consent abuse sits at the intersection of authorization, governance, and identity risk. A consented app may look normal in logs while still representing an access path the organisation never intended to create.

Consent injection often shows up as a misleading approval workflow, a malicious multi-tenant application request, or a permission prompt that hides the true scope of access. The user sees a familiar approval screen, but the application behind it is not trustworthy.

In practice, the abuse can involve overbroad scopes, deceptive branding, or a request that is technically valid but contextually fraudulent. The weakness is not the OAuth protocol itself, but the gap between human approval and the actual downstream privilege being granted.

Because these flows are designed to delegate trust, they are especially sensitive to social engineering, directory configuration, and tenant policies that allow broad app consent. That makes consent injection a governance problem as much as a technical one.

Security Implications and Control Boundaries

Consent injection turns a normal approval flow into a persistence mechanism. Once an application is granted access, it can continue operating through legitimate tokens and permissions even after the original lure is forgotten.

That creates a boundary problem for defenders: the application is not necessarily malicious at first glance, and the approval may have been made by a real user or administrator. The control objective is therefore to reduce surprise, constrain scope, and make approval decisions more visible and reviewable.

The privacy and authorization implications are significant enough that the issue also maps cleanly to the GDPR, especially where consent, data minimisation, and security of processing intersect with directory or application access.

Risk and Threat Considerations

Consent injection is risky because it converts a trusted approval mechanism into an attacker-controlled access grant. The resulting application may obtain persistent access to identity data, business data, or directory functions without needing the victim’s password again.

Failure mechanism: A malicious or misleading app request secures a legitimate consent grant, and the directory or OAuth platform treats that approval as an authoritative delegation of access.

Impact: The attacker can keep using the granted permissions for data access, mailbox access, or directory abuse until the consent is discovered and revoked.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and OWASP ASVS set the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-16 — Security and Privacy AttributesConsent injection abuses delegated access decisions and permission scope
IA-5 — Authenticator ManagementOAuth consent abuse ultimately depends on secret, token, and grant lifecycle control
AU-2 — Event LoggingConsent grants must be visible enough to detect suspicious approval events
Recommendation — Constrain app consent with attribute-based approval rules and scope limits. Tighten token and secret lifecycle controls so consented access can be revoked quickly. Log consent grants and admin approvals so anomalous app access can be investigated.
OWASP ASVSV10 — OAuth and OIDCOAuth consent screens and delegated authorization are the core mechanism abused here
Recommendation — Review OAuth and OIDC consent handling for scope restriction and safe authorization flows.
GDPRArt.25 — Data protection by design and by defaultConsent injection can expose personal data through overbroad delegated access
Recommendation — Design consent flows to minimise data exposure and default to narrow permissions.

Practitioner Guidance

Governance implication: Treat consent as an access-granting event, not a user-interface step. Organisations should distinguish low-risk user consent from high-risk admin consent and make it easy to review who approved what, when, and for which scopes.

What to watch for: Repeated consent prompts, unusually broad scopes, unfamiliar multi-tenant apps, and approvals that do not match normal business usage deserve scrutiny. In a well-run environment, consent should be narrow, deliberate, and reversible.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org