Application Secret Added Then Used for Mailbox Access
This rule monitors for the addition of new credentials (secrets) to service principals or applications in an Azure/Entra ID environment. It then correlates this event with subsequent mailbox activity (such as accessing mail items, sending mail, or message binding) performed by the application within 7 days of the credential creation. This detection pattern is indicative of potential OAuth application-based persistence and mailbox data exfiltration.
Microsoft Sentinel (KQL)

