Anomalous Google Workspace OAuth token usage from unfamiliar IP/device
This rule detects new or anomalous Google Workspace OAuth authorization events by monitoring for actions related to OAuth, consent, tokens, or authorization from IP addresses, geographical locations, or devices that have not been observed for the specific user account within the past 30 days.
Microsoft Sentinel (KQL)

