OAuth Token/Session Replay Leading to Sensitive SaaS Actions

Detects instances where a user successfully authenticates to a cloud service (Azure AD) from an unrecognized ASN, device, or country without performing MFA, followed shortly by high-risk actions such as mailbox rule creation, mass file downloads, or OAuth application registration. This pattern is indicative of session cookie theft or OAuth token replay used to bypass MFA.