Best Detection of 2026 Series: OAuth Consent Grant Abuse (ConsentFix)

Detects instances where a user account consents to an OAuth application requesting high-privilege or sensitive scopes such as Mail.Read, Files.ReadWrite.All, or offline_access. This behavior is a common indicator of consent phishing attacks, where adversaries trick users into granting persistent access to their cloud resources via malicious OAuth applications.