my summary :
• App registration/Service Principal without connection to Microsoft366, Google or Salesforce is recognized as an Oaut app in the incident but is not listed in the Governance app.
• The App Page for this type of Oauth Apps can only be opened within the incident.
• There is no query for Status Approved in KQL (OAuthAppInfo), only Enabled or Disabled
• No reference to Approved found via Powershell.
• With the Object ID you can find the app in Defender / Assets / Identities, but also no "Approved" note.
• There is no notice in Entra ID / Enterprise Apps either
Guess it's just an internal classification in the Defender Incident that isn't really listed anywhere.
Manual documentation is probably the current solution.
Consultants, Copilot and GPT coudn't help either ;-)
I appreciate any advises.