Possible Rogue Device Registration in Entra ID After Device Code Phishing

PremiumReviewedSigma · Medium · v1
Product
azure
Service
auditlogs
Author
HuntRule
Published
2026-06-11
Updated
2026-08-28

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects registration of a new device in Entra ID which commonly follows successful device-code phishing. In the Dangerous Invitations campaign the Russian actor registered attacker-controlled devices to obtain durable access after luring targets with spoofed European security event invitations. Adding a rogue device is a stealthy persistence mechanism that can bypass conditional access and sustain access to the tenant.

Related detections3 linkedT1098.005 — drag to rearrange
Suspicious Device Registration Following OAuth Token Theft
Suspicious Workday Payment Election Change via Compromised Account (via workday)
Suspicious Exchange Online Mail Flow Rule or Connector Creation via Compromised Account
Possible Rogue Device Registration in Entra ID After Device Code Phishing
Pivot detection · T1098.005 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.