Microsoft 365Detection & ResponseRetrospectives

Detecting OAuth App Abuse: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2024, written in 2026 with the benefit of hindsight.

OAuth application abuse lets attackers access mailboxes and data with app-level permissions that bypass user MFA. These detections focus on privilege escalation through apps.

Signals worth watching

  • New app role assignments granting high-privilege permissions (for example, full_access_as_app, Mail.ReadWrite, RoleManagement.ReadWrite.Directory).
  • New service principals created in your tenant for apps registered in other tenants.
  • Apps granted consent by newly created user accounts.
  • Apps accessing many mailboxes via MailItemsAccessed.
  • Service principal sign-ins from residential proxy IPs or unfamiliar ASNs.

Where the data lives

  • Entra ID audit logs: "Add app role assignment to service principal," "Add service principal," "Consent to application."
  • Service principal sign-in logs.
  • Purview audit logs for mailbox access by apps.
  • Defender for Cloud Apps app governance alerts.

A starting query

High-privilege app role assignments:

AuditLogs
| where OperationName == "Add app role assignment to service principal"
| extend Props = tostring(TargetResources[0].modifiedProperties)
| where Props has_any ("full_access_as_app", "Mail.ReadWrite", "Mail.Read", "RoleManagement.ReadWrite.Directory",
    "AppRoleAssignment.ReadWrite.All", "Directory.ReadWrite.All", "Files.ReadWrite.All")
| project TimeGenerated, InitiatedBy, TargetResources

Response

  1. Remove the app role assignment and disable the service principal.
  2. Review mailboxes and data accessed by the app.
  3. Investigate the identity that granted the permission.
  4. Search for other apps created or modified by the same actor.
detect oauth app abuseMidnight Blizzard breaches Microsoft2024

More on this story