Unusual OAuth Application Consent Grant with High Privilege Scopes
This rule detects when a user grants an OAuth application consent to access high-privilege scopes in an Azure environment. It specifically flags instances where the consent is not for all principals and the user performing the action is not a Global Administrator, which may indicate an attacker-controlled application being granted access to sensitive data or resources.
Microsoft Sentinel (KQL)

