CA Bypass via PRT Exchange for AAD Graph Token with Compliant Device Claim

This rule detects potential Conditional Access bypass attempts where a Primary Refresh Token (PRT) is exchanged for an Azure Active Directory (AAD) Graph token. The detection specifically looks for successful sign-ins to 'Windows Azure Active Directory' or 'Microsoft Graph' resources from devices marked as 'compliant' but with 'Unknown' ownership or no prior device registration history in Audit Logs. This could indicate an adversary using a compromised PRT on an unregistered or untrusted device to gain access to resources that should be protected by Conditional Access policies.