Business email compromise does not always end when a password is changed.
In Microsoft 365 environments, attackers may look for ways to maintain access, collect data, or continue activity after gaining control of an account. One way that can happen is through application consent.
When users grant permissions to an application, that app may receive access to certain information or actions inside the environment. In many cases, this is part of normal business. Employees connect productivity tools, scheduling apps, email clients, and other services to make their work easier.
But not every consented application belongs in your tenant.
A suspicious application may request access that does not match its purpose. It may appear after an account compromise. It may be assigned to a small number of users with no clear business reason. Or it may remain in the environment long after the original security event has been resolved.
That is why suspicious applications with consent deserve attention. The security lesson is not that every connected app is dangerous. The lesson is that application permissions can create lasting identity risk if your team does not have visibility into what has been granted, who approved it, and whether it still belongs.
Consented applications are apps that have been granted permission to access resources in your Microsoft 365 or Entra ID environment. Depending on the permissions granted, an app may be able to read profile information, access email, interact with files or perform other actions.
Some application consent is expected. Many organizations rely on third-party tools that connect to Microsoft accounts or business data. Those apps may support normal work and may be approved as part of your IT process.
The concern begins when an application has permissions it should not have.
For example, an application may deserve review if it was consented by an unexpected user, appears after suspicious login activity, has permissions that seem too broad or is connected to an account that was previously involved in a business email compromise. It may also be concerning if the app is unfamiliar to your IT team or does not align with approved business use.
A consented application is not automatically malicious. Its risk depends on context.
An approved business app with the right permissions may be normal. An unfamiliar app with access to mail, files, or user data may require further investigation. The application itself is only one part of the picture. The surrounding account activity, permissions, timing and business purpose are what help determine whether it belongs.
That is why application consent matters from a security operations perspective. It gives your team another identity layer to monitor beyond passwords, MFA and sign-in activity.
Attackers do not always need to keep logging in with a stolen password to create risk. If they can get an application approved, they may be able to retain access through the permissions granted to that app.
That makes application consent an important place to look during threat hunting.
When your security team reviews consented applications, they are not only asking whether an app exists. They are asking whether the application makes sense for the environment.
Who consented to it?
What permissions were granted?
Which users are assigned to it?
Was it approved through a normal process?
Did it appear near suspicious login or email activity?
Does the app have a clear business purpose?
Those questions matter because suspicious consented applications can support activity that is harder to spot than a standard login event. An attacker may use application permissions to access email, collect data, send messages, or maintain access in a way that does not look like a normal interactive sign-in.
This is where threat hunting can add value beyond standard alerting.
A standard alert may detect a risky login, blocked sign-in, or known malicious behavior. A threat hunt can take a broader view and ask whether any applications still have access that should be removed, reviewed, or restricted.
For suspicious consented applications, the better question is not simply, “Was an application approved?” Applications are approved in Microsoft 365 environments all the time. The better question is, “Does this app have the right level of access for the right reason?”
A mature hunt looks for relationships between users, applications, permissions, sign-in activity, and business context. It helps your security team separate expected application use from permissions that may have been granted during or after a compromise.
That visibility is important because identity risk can persist after the obvious incident is resolved. A password reset may help secure the user account, but it does not automatically answer whether a suspicious application still has access. Threat hunting helps your team validate that the environment is clean beyond the initial login event.
Suspicious consented applications are a reminder that identity security is more than controlling who can sign in.
Your security program also needs visibility into what applications can access your environment, what permissions they have, and whether those permissions are still appropriate. This is especially important in Microsoft 365 environments where users may be able to connect third-party apps that interact with email, files, or other business data.
A stronger security program needs a practical way to answer questions like:
Can we see which applications have been granted access?
Do we know who consented to each application?
Can we tell which users are assigned to the app?
Do we understand what permissions were granted?
Can we identify applications connected to suspicious account activity?
Do we have a process for removing or restricting unauthorized applications?
Are we reviewing consent settings before they become a bigger issue?
The goal is not to block every application by default without considering business needs. That can create friction and push users toward workarounds. The goal is to create a clear process for reviewing application access, limiting unnecessary permissions, and investigating anything that does not fit the environment.
This also matters after a business email compromise. If your response process stops at resetting a password, you may miss other access paths that were created while the attacker had control of the account. Application consent should be part of the broader identity review.
When your team can see application permissions, understand the context, and respond quickly, identity security becomes more than sign-in protection. It becomes an ongoing practice of validating who and what has access to your environment.
Suspicious consented applications are one example of a larger security challenge: knowing when identity access has changed in ways that may increase risk.
DotStar helps organizations and MSP partners move beyond passive monitoring by turning security data into visibility, context, and action. Our managed security services support identity monitoring, threat hunting, detection refinement, reporting, and response workflows so your team can better understand what changed, why it matters, and what to do next.
The goal is not just to generate more alerts. It is to help you build a stronger security program over time.