Device Registration Abuse After Risky Sign-in to Bypass MFA (T1098.005)

Detects a sequence of events where a user with a high-risk or compromised sign-in status registers a new device in Entra ID shortly after the event, followed by subsequent sign-ins from that device that bypass multi-factor authentication (MFA) via Conditional Access policies.