{
  "slug": "oauth-consent-persistence",
  "title": "You changed the password. The app you authorised in 2023 is still reading your mail.",
  "summary": "OAuth consent grants survive password resets, MFA changes and incident response. Why nobody can say who approved an app, and what a signed grant would change.",
  "lede": "A password reset feels like closing a door. For OAuth consent grants it is not even a gesture at the door. The grant was a separate act, it lives in a separate place, and in most configurations it keeps working long after the incident ticket is marked resolved.",
  "date": "2026-09-15",
  "reading_time": "16 min read",
  "category": "Security",
  "tags": ["OAuth consent", "illicit consent grant", "refresh token", "Microsoft 365", "persistence", "incident response", "authority"],
  "image": "https://cdn.twc.sh/images/igcache/OAuth%20Consent%20Persistence/1200_630/blog.jpg",
  "url": "/blog/oauth-consent-persistence.html",
  "wordcount": 3676,
  "related": ["device-code-phishing", "revocation-that-propagates", "authority-graph"],
  "schema": "Article"
}
