Rogue app/service principal registered with external-auth callback + ngrok reply

Detects the creation of an application registered with a specific Microsoft external authentication provider URI, immediately followed by the configuration of its service principal with reply URLs pointing to external tunneling services like ngrok. This sequence is indicative of an attacker attempting to register a rogue MFA provider to intercept authentication requests.