Microsoft Defender XDR
General

OAuthAppInfo (Preview)

In brief

The documentation now lists the `RiskScore` and `AssignedRoles` columns, and clarifies that data for Entra managed identities is excluded. The article date was also updated.

What Defender admins need to know

No action is required. Review the updated schema and coverage notes when building or maintaining advanced hunting queries.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

OAuthAppInfo (Preview)

The OAuthAppInfo table in the advanced hunting schema contains information about Microsoft 365-connected OAuth applications in the organization that are registered with Microsoft Entra ID and available in the Microsoft Defender for Cloud Apps app governance capability.

The OAuthAppInfo table might not include all the app or service principal-related properties that are available on Entra ID. It also doesn't include data related to Microsoft first-party apps or apps without any OAuth consents.Entra managed identities. The coverage of the table is based on the existing scope of Microsoft 365-connected apps covered by app governance.

Prerequisites

| AppOrigin | string | Specifies whether the app is internal to the organization or registered in an external tenant| | LastUsedTime | datetime | Date and time when the app last signed in. Tracking of this data goes back to June, 2022| | AppOwnerTenantId | string |Specifies the ID of the tenant where the app was registered| | RiskScore | integer | The risk score of the app as calculated by Microsoft Defender| | AssignedRoles | dynamic | Active roles assigned to the service principal. This currently covers only Entra roles.|

The OAuthAppInfo table updates information on an hourly basis to record any changes in metadata or insights for OAuth apps based on data from Defender for Cloud Apps app governance.