OAuth consent grant to unfamiliar app requesting high-risk scopes

Detects potential consent phishing attempts by identifying when a user grants high-risk, persistent-access OAuth scopes (such as Mail or Files) to a new third-party application. The rule specifically excludes known first-party Microsoft apps and utilizes a lookback period to avoid alerting on applications that have already been consented to within the tenant, reducing noise from routine enterprise app usage.