Successful Device Code OAuth Sign-in

This rule detects successful sign-ins using the OAuth 2.0 Device Code Flow. This flow is often abused in phishing attacks (device code phishing) where an attacker tricks a user into authenticating a malicious application. A successful sign-in using this method could indicate a compromised account or a successful phishing attempt.