Phantom Device Registered to Azure AD via Device Code Flow Targeting DRS

Detects suspicious device registrations to Azure AD's Device Registration Service (DRS) using the device code flow. This rule identifies registrations where the device OS attributes are suspicious (e.g., version 0.0.0.0) or where a non-Windows OS claims a Windows identity, potentially indicating an adversary attempting to bypass conditional access policies or gain persistent access.