2026 Critical Enterprise Intrusion Chain Detection: Malicious OAuth Application Consent Following Anomalous Sign-In
This rule detects scenarios where a user account grants high-privilege permissions (e.g., mail access or file modification) to an OAuth application within a short time frame (2 hours) following a sign-in event flagged as risky by Entra ID (Azure AD). This pattern is indicative of an adversary abusing OAuth consent flows as a persistence and credential-access mechanism following account compromise.
Microsoft Sentinel (KQL)

