Post device-code token reuse: high-volume Graph API access from new device
Detects potential abuse of the Microsoft Graph API by correlating device-code authentication events with subsequent high-volume activity, such as mail or file enumeration, from the same account within a short window. This pattern is indicative of ARToken-style token proxying, where an attacker intercepts an OAuth device-code token to gain unauthorized access to an user's resources.
Microsoft Sentinel (KQL)

