The FBI's September warning describes consent phishing against prominent people and contacts. The interesting containment failure is not credential theft: a legitimate provider screen lets the user authorize an attacker-controlled app. Changing the password does not remove that delegated grant.
The user was probably trying to open a file or accept an invitation, not assess an application's permissions under time pressure. For protected accounts, direct consent to unmanaged apps should be restricted, but that moves pressure to reviewers and to adjacent staff who handle the principal's work. An allowlist without a usable exception route is asking for workarounds.
A useful drill: identify the client ID and scopes, remove the grant, and test whether the app can still make a permitted API call.
Our analysis separates Entra and Workspace controls rather than assuming the same workflow exists in both.