CA Bypass via PRT Exchange for AAD Graph Token with Compliant Device Claim

This rule detects attempts to bypass Conditional Access policies by exchanging a Primary Refresh Token (PRT) for an Azure Active Directory (AAD) Graph token on a device that is either of 'Unknown' ownership or lacks a check-in history, despite being marked as compliant. This behavior could indicate an adversary attempting to gain unauthorized access to resources by leveraging a compromised PRT on an unmanaged or suspicious device, circumventing Conditional Access controls.