Suspicious Application Consent in Azure AD

This rule detects suspicious application consent activity in Azure AD. It identifies instances where a user successfully grants consent to three or more applications within a one-hour window. This behavior can indicate an adversary attempting to gain access to resources by tricking users into consenting to malicious applications.