GuideInformationCybersecurityIT

Do not treat an app-governance activity count as a retained Graph audit trail

Why might an OAuth threat alert show a spike without containing every underlying API activity?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseGuide · 2 min read
Executive summary

What you need to know

Why might an OAuth threat alert show a spike without containing every underlying API activity?

Potentially affected

OAuth application threat-detection alerts generated by Defender for Cloud Apps app governance.

DSE recommendation

Preserve the alert's aggregate indication and collect available activity records as separate evidence sources.

Source facts

Microsoft says app-governance threat detection counts activities using transient data that may not be stored. An alert can therefore report a count or spike without including every related activity. For OAuth applications’ Microsoft Graph calls, the tenant can audit the activities through Log Analytics and Sentinel. The documented detections are nondeterministic and depend on behavior departing from the norm. Microsoft Learn.

Applicability

Identify the app-governance alert, application and interval under investigation. Determine which activity logging was actually available for that interval; the documentation does not establish that it was configured in your tenant. Keep the alert’s aggregate observation distinct from individually retrievable calls and from an analyst’s conclusion.

DSE recommendation

Preserve the alert’s aggregate indication and collect available activity records as separate evidence sources. Have the application owner explain expected activity while the responder examines the recorded calls, permissions and relevant changes. Mark missing underlying records as an evidence limitation rather than inventing a transaction list from the displayed count. For future investigations, review the tenant’s Graph activity-audit coverage and access with the logging owner.

Verification

Compare the alert’s time and application identity with the available audit records, noting differences in coverage instead of forcing their totals to agree. Document which conclusions are supported by individual events and which rely only on the aggregate detection. In a controlled readiness exercise, verify that authorized responders can retrieve expected Graph activity through the configured logging path. Do not use the absence of a reproducible alert as a test of whether those records were retained.

Official references

Microsoft Learn: Investigate OAuth app threat detection alerts. Source reviewed September 9, 2026.

Primary reference

Review the official source

Investigate OAuth app threat detection alerts with app governance - Microsoft Defender for Cloud Apps | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE