Microsoft Defender for Cloud Apps
Cloud and workloads

Investigate OAuth app threat detection alerts with app governance | Microsoft Defender for Cloud Apps

In brief

The guide now explicitly lists alert categories from Initial Access through Impact, clarifies discovery-alert descriptions, and streamlines links and remediation instructions.

What Defender admins need to know

Administrators get clearer guidance for investigating and remediating app governance alerts. No configuration or migration action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Investigate OAuth app threat detection alerts with app governance | Microsoft Defender for Cloud Apps ms.date: 06/16/07/03/2026 ms.topic: how-to ms.custom: has-azure-ad-ps-ref, azure-ad-ref-level-one-done, msecd-doc-authoring-10141016 description: Learn how to investigate threat detection alerts from app governance in Microsoft Defender XDR with Microsoft Defender for Cloud Apps. ms.reviewer: shragar ai-usage: ai-assisted

The MITRE ATT&CK framework is an industry-standard knowledge base of adversary tactics and techniques. To make it easier to map the relationship between app governance alerts and the MITRE ATT&CK Matrix, we've categorized the alerts by their corresponding MITRE ATT&CK tactic. This extra reference makes it easier to understand the suspected attacks technique potentially in use when app governance alert is triggered.

This guide provides information about investigating and remediating app governance alerts in the following categories.for Initial Access, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Exfiltration, and Impact.

Understand the scope of the breach

Follow the tutorial on how toFor more information, see Investigate risky OAuth apps.

OAuth App with Read scopes has suspicious Reply URL

  • TP: If you can confirm that inbox rule was created by an OAuth third-party app with suspicious scopes delivered from an unknown source, then a true positive is detected.

    Recommended action: Disable and remove the app, reset the password, and remove the inbox rule.

Follow Reset the tutorial on how to Reset a password using Microsoft Entra ID and follow the tutorial on how to remove the inbox rule.

  • FP: If you can confirm that app created an inbox rule to a new or personal external email account for legitimate reasons.

  • TP: If you can confirm that inbox rule was created by an OAuth third-party app with suspicious scopes delivered from an unknown source, then a true positive is indicated.

    Recommended action: Disable and remove the app, reset the password, and remove the inbox rule.

    Follow Reset the tutorial on how to Reset a password using Microsoft Entra ID and follow the tutorial on how to remove the inbox rule.

  • FP: If you can confirm that app created an inbox rule to a new or personal external email account for legitimate reasons.

Discovery alerts

The following discovery alerts indicate that a malicious app may be attempting to map your organization's environment by enumerating resources, accounts, or data.

App performed drive enumeration

Severity: Medium

  • TP: If you can confirm that the unusual graph activity was performed by the Line of Business (LOB) OAuth App, then a true positive is indicated.

    Recommended actions: Temporarily disable the app and reset the password and then re-enable the app. FollowReset the tutorial on how to Reset a password using Microsoft Entra ID.

  • FP: If you can confirm that the app is intended to do unusually high volume of graph calls.

Next steps

After investigating alerts, learn how to manage and resolve them:app governance alerts: