Device Code Phishing: Suspicious Auth Followed by Sensitive Graph API Calls

This rule detects potentially compromised accounts by correlating successful device code authentication events that exhibit anomalous characteristics (such as first-time usage, high/medium risk scores, or non-compliant/unmanaged device status) with highly sensitive Azure AD/Graph API administrative operations occurring within 30 minutes of the sign-in.