Mass Exchange Online Mailbox Exfil via REST API (One Outlook Web)

Detects high-volume API requests to Exchange REST services using a specific application ID or Outlook Web branding, where the account object ID is missing. This pattern is indicative of potential OAuth token abuse, where an attacker utilizes a stolen token to perform automated actions without the presence of a legitimate user session.