Admin Consent Granted for Privileged Directory/Role Write Scopes

Detects instances where a user grants consent to an Azure AD application with highly sensitive permissions (such as ReadWrite access to Directory, Roles, or Applications). This pattern is commonly used in OAuth consent phishing attacks to maintain persistence or escalate privileges by authorizing a malicious application to act on behalf of the user or the entire directory.