2026 Critical Enterprise Intrusion Chain Detection: Anomalous OAuth App Consent Following Risky Sign-In
Detects instances where a user account identified as high or medium risk, or marked as 'at risk' by Azure AD Identity Protection, performs an OAuth application consent action within one hour of the risky sign-in event. This correlation targets potential illicit application consent attacks where a compromised account is used to grant permissions to a malicious application.
Cortex XDR

