You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Rules: Suspicious Azure Active Directory Device Code Authentication
Description
Successful Device Code authentication flows result in the issuance of an Azure Primary Refresh Token which can be used to access, enumerate or - if the relevant permissions exist - to modify Azure resources.
Additional Details
Detail
Value
Type
Templated Match
Category
Initial Access
Apply Risk to Entities
srcDevice_ip, user_username
Signal Name
Suspicious Azure Active Directory Device Code Authentication
Summary Expression
A successful & suspcious Device Code authentication flow was completed to access the Azure resource: {{application}} for the user: {{user_username}}