Detecting OAuth App Abuse: Defender XDR and Sentinel Hunting Queries
Retrospective: this article looks back at events from January 2024, written in 2026 with the benefit of hindsight.
OAuth application abuse lets attackers access mailboxes and data with app-level permissions that bypass user MFA. These detections focus on privilege escalation through apps.
Signals worth watching
- New app role assignments granting high-privilege permissions (for example,
full_access_as_app,Mail.ReadWrite,RoleManagement.ReadWrite.Directory). - New service principals created in your tenant for apps registered in other tenants.
- Apps granted consent by newly created user accounts.
- Apps accessing many mailboxes via
MailItemsAccessed. - Service principal sign-ins from residential proxy IPs or unfamiliar ASNs.
Where the data lives
- Entra ID audit logs: "Add app role assignment to service principal," "Add service principal," "Consent to application."
- Service principal sign-in logs.
- Purview audit logs for mailbox access by apps.
- Defender for Cloud Apps app governance alerts.
A starting query
High-privilege app role assignments:
AuditLogs
| where OperationName == "Add app role assignment to service principal"
| extend Props = tostring(TargetResources[0].modifiedProperties)
| where Props has_any ("full_access_as_app", "Mail.ReadWrite", "Mail.Read", "RoleManagement.ReadWrite.Directory",
"AppRoleAssignment.ReadWrite.All", "Directory.ReadWrite.All", "Files.ReadWrite.All")
| project TimeGenerated, InitiatedBy, TargetResources
Response
- Remove the app role assignment and disable the service principal.
- Review mailboxes and data accessed by the app.
- Investigate the identity that granted the permission.
- Search for other apps created or modified by the same actor.
- Midnight Blizzard Breaches Microsoft (Jan 2024): A Legacy Test Tenant and an OAuth App Incident Teardowns
- How to Find Forgotten Test Tenants and Over-Privileged OAuth Apps How-To & Hardening
- CIO Brief: The Test Environment Nobody Remembered CIO Briefings