https://techygeekshome.info/remove-deny-permissions-from-exchange-mailbox-using-powershell/?fsp_sid=3132
We've run a packet capture of the "Admin" app when it is launched, and it sends a GET request to admin.microsoft.com as I would expect, followed by the SSO login to login.microsoft.com, then back to admin.microsoft.com. The traffic is as expected for accessing admin.microsoft.com
The Microsoft 365 Admin app description looks dodgy-as, but all indicators is that it is legitimate.
#infosec #office365 #office365admin #microsoft365 #microsoft365admin
UPDATE: The app appears to be legitimate.
Does anyone know if Microsoft365 updated their "app" today? When logging into the admin center, we got a dodgy notification that the app has been installed. All the writing is in Arabic (I've seen other reports of it being in Russian).
We haven't found any evidence of it being installed in any logs.
The link shown in myapps is seemingly legitimate and goes to the office365 admin portal.