OAuth Token/Session Replay Leading to Sensitive SaaS Actions
Detects instances where a user successfully authenticates to a cloud service (Azure AD) from an unrecognized ASN, device, or country without performing MFA, followed shortly by high-risk actions such as mailbox rule creation, mass file downloads, or OAuth application registration. This pattern is indicative of session cookie theft or OAuth token replay used to bypass MFA.
Microsoft Sentinel (KQL)

