2026 Critical Enterprise Intrusion Chain Detection: Malicious OAuth Application Consent Grant Post-Compromise

Detects the granting of high-risk OAuth application scopes (e.g., Mail.Read, offline_access) within two hours of a risky sign-in event for the same user. This pattern is indicative of attackers establishing persistence and maintaining access to sensitive data (such as emails or files) even after potential credential resets.