Unusual Exchange Mailbox Access Activity

Detects mailbox access events from IP addresses or networks uncommon for the user. Frequently observed after successful token theft.

Microsoft Sentinel (KQL)