How I investigated OAuth scope alerts without locking out the wrong app
I ran into this in a security review after our SIEM flagged a service account for requesting a broader OAuth scope. The issue was the alert named a production integration, but the actual token activity did not match that service owner. At first I blamed an active credential compromise, but it showed up whenever a vendor rotated its app registration and reused a similar display name. This caused…