Phishing Series 2026: Microsoft 365 Device-Code Authentication Phishing — Unfamiliar App + Burst Sign-Ins
Detects potential OAuth device code phishing attempts by identifying sign-ins via the device code flow using applications not previously used by the specific user, especially when occurring in a burst pattern across multiple users.
Microsoft Sentinel (KQL)

