Device Code Authentication From Known Suspicious Hosting Networks

Identifies device code sign-ins originating from infrastructure previously associated with phishing operations and adversary-controlled relay servers.

Microsoft Sentinel (KQL)