T1566 Phishing - Successful Device Code Phish Device Add
This query identifies a device being added to an Entra ID account following a suspected successful device code phish attempt as evidenced by the sign in method displaying "deviceCodeFlow". Attackers have been known to register a new device shortly after compromising a user account to establish persistence in the form of Primary Refresh Tokens (PRTs) generated by the attacker-controlled device.
Microsoft Sentinel (KQL)

