High-Risk OAuth Application Consent by Non-Admin User
This rule detects when a non-administrative user grants an application high-privilege OAuth scopes (such as mail reading, file access, or directory management) within an Azure/Microsoft 365 environment. Such consent grants can be used by attackers to maintain persistence and bypass MFA by gaining delegated access to sensitive resources.
Microsoft Sentinel (KQL)

