2026 Critical Enterprise Intrusion Chain Detection: Malicious OAuth Application Consent Grant Post-Compromise
Detects the granting of high-risk OAuth application scopes (e.g., Mail.Read, offline_access) within two hours of a risky sign-in event for the same user. This pattern is indicative of attackers establishing persistence and maintaining access to sensitive data (such as emails or files) even after potential credential resets.
Microsoft Sentinel (KQL)

