Phishing Series 2026: Microsoft 365 Device-Code Authentication Phishing — Unfamiliar App + Burst Sign-Ins

Detects potential OAuth device code phishing attempts by identifying sign-ins via the device code flow using applications not previously used by the specific user, especially when occurring in a burst pattern across multiple users.