2026 Critical Cloud Identity Detection: Legacy or Unmanaged Device Refresh Token
This rule detects non-interactive sign-in events using AzureAD tokens from unmanaged devices. This pattern is indicative of potential session or refresh token hijacking, where an adversary replays a stolen session token from their own environment. While a single event is not definitive for impossible travel, it serves as a high-confidence seed for identifying compromised sessions when combined with other indicators.
Sigma

