Suspicious Device Code Authentication via Microsoft Authentication Broker

PremiumReviewedSigma · High · v1
Product
azure
Service
signinlogs
Author
HuntRule
Published
2026-09-27
Updated
2026-09-27

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects device code authentication requests targeting the Microsoft Authentication Broker application, identified by its client identifier 29d9ed98-a469-4536-ade2-f981bc1d605e, which attackers abuse to obtain a Primary Refresh Token during device code phishing. A stolen PRT provides broad, durable access to the victim tenant. This combination is a high-confidence indicator of an OAuth device code phishing attack.

Related detections9 linkedT1528 — drag to rearrange
Possible Illicit Consent Grant to OAuth Application via Azure AD
Suspicious OAuth Device Code Sign-In to Authentication Broker via Tycoon 2FA
Suspicious OAuth Sign-In Using Visual Studio Code Client and Auth Broker
Suspicious OAuth Application Consent in Microsoft Entra
Malicious OAuth Application Granted Full Mailbox and EWS Permissions (via m365)
Suspicious GAM OAuth Token Enumeration via Process Creation
Suspicious Entra ID Device Code Flow Authentication
Suspicious Delegated Permission Grant to Entra Agent Access Scope via Azure Audit Logs
Suspicious OAuth Application Registration with Localhost Reply URL via Azure AD
Suspicious Device Code Authentication via Microsoft Authentication Broker
Pivot detection · T1528 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.