Detecting Third-Party App Tenant Access: Defender XDR and Sentinel Hunting Queries
Retrospective: this article looks back at events from January 2021, written in 2026 with the benefit of hindsight.
A compromised third-party integration can access your tenant with the app's permissions. These detections focus on unusual behavior by third-party apps.
Signals worth watching
- A third-party app's service principal signing in from new IP addresses or regions.
- Sudden increases in mailbox access by an app.
- New permissions requested or granted to an existing vendor app.
- Vendor apps active outside their normal schedule (for example, a backup tool reading mail at unusual times).
- Vendor security advisories or Microsoft notifications about compromised certificates or apps.
Where the data lives
- Service principal sign-in logs (
AADServicePrincipalSignInLogs). - Unified audit log (
MailItemsAccessed, mailbox operations by apps). - Defender for Cloud Apps app governance alerts on unusual data usage.
- Entra ID audit logs for permission changes.
A starting query
Service principal sign-ins by IP, to establish a baseline and spot new sources:
AADServicePrincipalSignInLogs
| where ResultType == "0"
| summarize IPs = make_set(IPAddress, 20), Count = count() by ServicePrincipalName, AppId, bin(TimeGenerated, 1d)
Compare against previous weeks to flag apps signing in from new IP ranges, and check vendor-published IP ranges where available.
Response
- Contact the vendor to confirm activity.
- If suspicious, disable the service principal and remove credentials or consent.
- Review data accessed.
- Re-establish the integration only after the vendor confirms remediation.