Suspicious Entra ID Device Code Flow Authentication

PremiumReviewedSigma · Medium · v1
Product
azure
Service
signinlogs
Author
HuntRule
Published
2026-07-29
Updated
2026-08-28

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects Entra ID sign-ins performed through the OAuth device code flow which threat actors abuse in device code phishing campaigns to trick users into authorizing attacker-controlled sessions and obtain tokens for apps such as Azure AD PowerShell and the Microsoft Authentication Broker. Device code authentications with inconsistent user agent and location across a shared session are a hallmark of this phishing technique.

Related detections9 linkedT1528 — drag to rearrange
Malicious OAuth Application Granted Full Mailbox and EWS Permissions (via m365)
Suspicious GAM OAuth Token Enumeration via Process Creation
Suspicious Delegated Permission Grant to Entra Agent Access Scope via Azure Audit Logs
Suspicious OAuth Application Registration with Localhost Reply URL via Azure AD
Malicious PRT Token Forging via AADInternals (via ps_script)
Possible VMware Workspace ONE SSRF via instanceHealth hostName At-Injection (via webserver)
Suspicious AiTM Phishing Kit Session Validation Endpoint via Proxy
Suspicious Entra Device Code Authentication with Office Client and Automated User Agent
Suspicious Access to Kubernetes Service Account Token via Curl or Wget (via process_creation)
Suspicious Entra ID Device Code Flow Authentication
Pivot detection · T1528 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.