The token that never asks for MFA: connected apps in your Microsoft 365
More than 700 organisations were potentially exposed in August 2025 without a single password being stolen: the attacker took the OAuth tokens of an application they had connected themselves. On 13 July 2026 Microsoft published the map of a full year of that technique: two attack chains and not one suspicious sign-in. The part that fails is not the login, it is consent: how to inventory the applications connected to your tenant with two Graph queries, what each button actually switches off, and why changing the consent setting revokes nothing already granted.