2026 Critical Enterprise Intrusion Chain Detection: Device Code / Passkey Phishing Authentication Abuse
Detects a suspicious sequence of events where a user performs a device-code authentication flow from a previously unseen application, followed within a two-hour window by sensitive account activities such as OAuth application consent/registration or mailbox-related administrative operations. This behavior is characteristic of passkey-phishing campaigns designed to steal access tokens and achieve persistence or data access via malicious OAuth applications.
Microsoft Sentinel (KQL)

