Azure Device Code Token Theft: New IP/ASN + Cross-Location Refresh

This rule detects potentially malicious OAuth activity in Azure AD where a user performs a device code authentication flow, followed by a refresh token request from a different, anomalous IP address or geographical location. This behavior is indicative of an attacker who has successfully phished a device code from a user and is now attempting to maintain persistent access to the account via a stolen refresh token.