Detecting OAuth App Over-Permission: Defender XDR and Sentinel Hunting Queries
Retrospective: this article looks back at events from March 2018, written in 2026 with the benefit of hindsight.
OAuth apps with excessive permissions can read mail and files across your tenant without a password. Detecting risky consent grants is a core identity detection for Microsoft 365.
Signals worth watching
- New consent grants for high-impact permissions (mail, files, directory write).
- Consent granted by many users to the same unfamiliar app in a short time.
- Apps from unverified publishers, or with names imitating Microsoft products.
- Apps with reply URLs on unusual domains.
- Admin consent granted tenant-wide outside your normal change process.
Where the data lives
- Entra ID audit logs: "Consent to application" and "Add delegated permission grant" events.
- Defender for Cloud Apps app governance: risk scores and alerts for OAuth apps.
- Unified audit log: app activity accessing mail and files.
A starting query
AuditLogs
| where OperationName == "Consent to application"
| extend App = tostring(TargetResources[0].displayName)
| extend User = tostring(InitiatedBy.user.userPrincipalName)
| extend Props = tostring(TargetResources[0].modifiedProperties)
| where Props has_any ("Mail.Read", "Mail.ReadWrite", "Files.Read.All", "Sites.Read.All", "full_access_as_user")
| project TimeGenerated, User, App, Props
Response
- Review the app's publisher, permissions and reply URLs.
- If suspicious, disable the service principal and revoke its permission grants.
- Check what data the app accessed using audit logs.
- Reset sessions for users who consented, and tighten consent settings.