Skip to content

[New Rule] Entra ID End-User Consent to App With Mailbox and Offline Access Scopes - #6729

Open
earbona23 wants to merge 1 commit into
elastic:mainfrom
earbona23:entra-consent-mailbox-offline
Open

earbona23 wants to merge 1 commit into
elastic:mainfrom
earbona23:entra-consent-mailbox-offline

Conversation

@earbona23

Copy link
Copy Markdown

ES|QL rule over logs-azure.auditlogs-* (T1528). Deterministic scope-combination detection: non-admin consent to a third-party app requesting a high-risk mailbox scope together with offline_access. Complementary to the existing new-terms 'Illicit Consent Grant via Registered Application'. Passes: python -m detection_rules validate-rule.

@botelastic botelastic Bot added Domain: Cloud Integration: Azure azure related rules labels Sep 3, 2026
@cla-checker-service

cla-checker-service Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

💚 CLA has been signed

@earbona23
earbona23 force-pushed the entra-consent-mailbox-offline branch from b135fbd to 1a57aa0 Compare September 3, 2026 13:15
@terrancedejesus terrancedejesus self-assigned this Sep 29, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

2 participants