“Permissions requested”: think before you click Accept
Some phishing doesn’t want your password. It wants you to grant a malicious app access to your mailbox and files.
- A “Permissions requested” screen lets an app access your account. Read it before you accept.
- Check the publisher: a blue verified badge is a good sign; “Unverified” is a reason to stop.
- Don’t trust the app’s name or web address on their own — both are easy to fake.
- Does the permission list make sense? A PDF viewer has no reason to read and send your email.
- If you’re unsure, click Cancel and use the “Report it here” link.
- Review apps you’ve already approved — see the related guide below.
Based on: Microsoft Learn — Protect against consent phishing · Microsoft Learn — The consent experience
Related: Review the apps connected to your account
Still stuck after those?
You’ve done the right thing by trying. Send whedo.it a quick note — what you tried, what you saw — and a senior pair of eyes will be on it the same business day.