PGH Networks

ConsentFix and ClickFix: M365 Token Theft Aimed at SMBs

July 4, 2026· PGH Networks Team· 4 min readCloud & Microsoft 365
ConsentFix and ClickFix: M365 Token Theft Aimed at SMBs

What happened

Security researchers are tracking a fast-moving wave of Microsoft 365 account takeover attacks dubbed ConsentFix and ClickFix. According to reporting from BleepingComputer, attackers are using fake browser prompts and malicious OAuth consent flows to steal Microsoft 365 session tokens in as little as three seconds — and because they're grabbing tokens rather than passwords, standard multi-factor authentication (MFA) doesn't stop them.

The mechanics are deceptively simple. A user is nudged into "fixing" something — clicking a bogus CAPTCHA, a fake error message, or a "verify your account" prompt — and in doing so either pastes an attacker-supplied command or grants an OAuth app permission to their mailbox and files. From there, the intruder has authenticated access to Microsoft 365 without ever needing the user's password or MFA code. For the specific indicators of compromise and screenshots, we recommend reading the BleepingComputer piece directly.

black office rolling chairs and table

Why this matters for Pittsburgh SMBs

If your business runs on Microsoft 365 — and almost every professional services, CPA, legal, healthcare, financial, manufacturing, and defense firm we work with in Western PA does — this is aimed squarely at you. Attackers have figured out that mid-market companies (10–200 employees) are the sweet spot: enough valuable data to be worth the effort, rarely staffed with a 24/7 security operations team, and often relying on "we have MFA turned on" as the finish line for identity security.

The stakes vary by vertical, but they're all serious:

  • CPAs and financial services firms are heading into a busy season with client PII, W-2s, and wire-transfer authority sitting in Outlook and OneDrive. A hijacked mailbox is a launchpad for invoice fraud against your clients.
  • Legal practices face confidentiality obligations and matter-file exposure that can trigger client-notification duties and bar complaints.
  • Healthcare organizations face HIPAA breach-notification thresholds the moment ePHI leaves the tenant.
  • Defense contractors working toward or maintaining CMMC compliance need to treat any M365 token theft as a reportable incident touching CUI.
  • Manufacturers are frequent targets for business-email-compromise pivots into ACH and vendor-payment fraud.

The FTC Safeguards Rule and SOC 2 controls both assume you can detect and respond to unauthorized access — a rogue OAuth grant that quietly reads mail for weeks is exactly the scenario auditors ask about.

What to do about it this week

You don't need to overhaul your stack to blunt ConsentFix/ClickFix. Most of the mitigations are configuration changes plus user awareness. Here's a practical starting list:

  1. Restrict user consent for applications in Entra ID (Azure AD). Set user consent to "Do not allow" or to verified publishers only, and route all new OAuth app requests through an admin approval workflow. This single change kills the ConsentFix vector for most users.
  2. Audit existing enterprise applications and OAuth grants. Review the list of third-party apps with Mail.Read, Files.Read.All, or full mailbox access. Revoke anything unrecognized, unused, or granted by a non-admin. Verify with your IT team when the last review occurred.
  3. Turn on (or tighten) Conditional Access. Require compliant or hybrid-joined devices for M365 sign-ins, block legacy authentication, and consider sign-in frequency controls for high-risk roles (finance, executives, IT admins).
  4. Move toward phishing-resistant MFA. Passkeys, FIDO2 security keys, or Windows Hello for Business defeat token-theft flows in a way that SMS and app-code MFA do not. Start with admins and finance staff.
  5. Train users on the specific pattern. The tell for ClickFix is being asked to paste something into the Windows Run dialog, PowerShell, or a terminal — no legitimate CAPTCHA, Teams meeting, or document ever requires that. A 10-minute all-hands note this week is worth more than a quarterly training module.
  6. Enable and monitor the right logs. Confirm Unified Audit Log is on, Entra sign-in and audit logs are retained, and alerts fire on new OAuth consents, unusual mailbox rules, and impossible-travel sign-ins. If you can't answer "would we see this?" — that's the gap.
  7. Rehearse a token-theft response. Revoking a password isn't enough; you need to revoke refresh tokens, sign the user out of all sessions, remove suspicious app grants, and hunt for inbox forwarding rules and mailbox delegation changes.

How PGH Networks helps

This is the day-to-day work our team does for Pittsburgh SMBs: hardening Microsoft 365 tenants, tuning Conditional Access and consent policies, monitoring Entra ID sign-in telemetry, and running the incident-response playbook when something does slip through. Our cybersecurity team also maps those controls back to the compliance frameworks you actually answer to — HIPAA, SOC 2, CMMC, and the FTC Safeguards Rule — so the same work satisfies both your security posture and your auditor.

If you're not sure whether user consent is locked down in your tenant, or which OAuth apps currently have access to your company's mailboxes, that's a good 30-minute conversation to have this week. Reach out to PGH Networks at 724.888.7007 or through our contact form and we'll walk your environment against the ConsentFix/ClickFix checklist above and tell you exactly where you stand.

Share

Related reading

Azure Consulting in Pittsburgh, PA

Azure consulting in Pittsburgh, PA for small and mid-market firms: migration, security, FinOps, and Copilot enablement from a local team. Talk to an engineer.