Unusual Device Code Flow Sign-in from Unfamiliar Location

Detects Microsoft 365 sign-ins using the device code grant flow from an unusual location or a previously unseen/unmanaged device. This behavior is consistent with OAuth phishing abuse, specifically 'device code phishing' where an adversary tricks a user into entering a code/credentials on a malicious authorization page to obtain a device token.