version 26.6.4 · Self-Help · Printing~3 min read

“Permissions requested”: think before you click Accept

Some phishing doesn’t want your password. It wants you to grant a malicious app access to your mailbox and files.

  1. A “Permissions requested” screen lets an app access your account. Read it before you accept.
  2. Check the publisher: a blue verified badge is a good sign; “Unverified” is a reason to stop.
  3. Don’t trust the app’s name or web address on their own — both are easy to fake.
  4. Does the permission list make sense? A PDF viewer has no reason to read and send your email.
  5. If you’re unsure, click Cancel and use the “Report it here” link.
  6. Review apps you’ve already approved — see the related guide below.

Based on: Microsoft Learn — Protect against consent phishing · Microsoft Learn — The consent experience

Related: Review the apps connected to your account

Still stuck after those?

You’ve done the right thing by trying. Send whedo.it a quick note — what you tried, what you saw — and a senior pair of eyes will be on it the same business day.

+61 421 346 887
5.0
★★★★★ on Google · loading…
Read all on Google →