OAuth consent grant to unfamiliar app requesting high-risk scopes
Detects potential consent phishing attempts by identifying when a user grants high-risk, persistent-access OAuth scopes (such as Mail or Files) to a new third-party application. The rule specifically excludes known first-party Microsoft apps and utilizes a lookback period to avoid alerting on applications that have already been consented to within the tenant, reducing noise from routine enterprise app usage.
Microsoft Sentinel (KQL)

