Successful Device Code Authentication via microsoft.com/devicelogin

Detects successful authentication events in Azure SigninLogs that utilize the Device Code OAuth flow. Attackers may leverage this flow in phishing campaigns or to bypass MFA by tricking users into authorizing malicious devices, which can lead to subsequent token theft.