Entra role/account changes shortly after device-code sign-in (ARToken)
Detects high-risk administrative actions in Entra ID, such as role assignments, user creation, or password resets, occurring shortly after a user authenticates using the device code flow. This pattern is indicative of a post-compromise takeover where an adversary utilizes a stolen or coerced device code session to escalate privileges.
Microsoft Sentinel (KQL)

