Most Important Detection 2026: Malicious OAuth Application Consent Grant Abuse

This rule detects potential illicit consent grants to OAuth applications within Azure AD. It identifies applications requesting high-risk scopes (such as Mail.Read, Files.ReadWrite.All, etc.) that are not verified by a publisher, are granted by non-admin users, and subsequently exhibit high volumes of graph API calls (suggestive of unauthorized data access or exfiltration).