Microsoft 365Detection & ResponseRetrospectives

Detecting Third-Party App Tenant Access: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2021, written in 2026 with the benefit of hindsight.

A compromised third-party integration can access your tenant with the app's permissions. These detections focus on unusual behavior by third-party apps.

Signals worth watching

  • A third-party app's service principal signing in from new IP addresses or regions.
  • Sudden increases in mailbox access by an app.
  • New permissions requested or granted to an existing vendor app.
  • Vendor apps active outside their normal schedule (for example, a backup tool reading mail at unusual times).
  • Vendor security advisories or Microsoft notifications about compromised certificates or apps.

Where the data lives

  • Service principal sign-in logs (AADServicePrincipalSignInLogs).
  • Unified audit log (MailItemsAccessed, mailbox operations by apps).
  • Defender for Cloud Apps app governance alerts on unusual data usage.
  • Entra ID audit logs for permission changes.

A starting query

Service principal sign-ins by IP, to establish a baseline and spot new sources:

AADServicePrincipalSignInLogs
| where ResultType == "0"
| summarize IPs = make_set(IPAddress, 20), Count = count() by ServicePrincipalName, AppId, bin(TimeGenerated, 1d)

Compare against previous weeks to flag apps signing in from new IP ranges, and check vendor-published IP ranges where available.

Response

  1. Contact the vendor to confirm activity.
  2. If suspicious, disable the service principal and remove credentials or consent.
  3. Review data accessed.
  4. Re-establish the integration only after the vendor confirms remediation.
detect third-party app tenant accessMimecast certificate2021

More on this story