TrustSink: Unfamiliar Issuer Claims Hardware Key

Detects Azure sign-in events claiming successful hardware-key or FIDO2 authentication where the authentication issuer is not part of a known-good allow-list. This behavior is indicative of a rogue MFA provider, such as the TrustSink attack, which issues forged tokens claiming MFA requirements were satisfied.