Suspicious Azure AD OAuth Application or Service Principal Registration
Detects suspicious OAuth application or service principal registration, or permission consent, performed by users who are not part of designated IT administrator groups. This rule flags high-privilege permission grants (e.g., Mail.Read, Directory.ReadWrite.All) or application consent events, which are common methods for establishing long-term persistence in cloud environments.
Microsoft Sentinel (KQL)

