App Granted Tenant-Wide Mailbox/File Application Permission
Detects the assignment of high-privilege application permissions (e.g., Mail.ReadWrite, full_access_as_app, Files.ReadWrite.All, Sites.FullControl.All) to a service principal. This pattern is indicative of an attacker who has compromised an Application Administrator account and is attempting to establish long-term, unattended access to cloud resources such as mailboxes and SharePoint sites via OAuth client-credential flows.
Microsoft Sentinel (KQL)

