Device registration/PRT issuance shortly after device-code sign-in
Detects a suspicious pattern where a user authenticates via device code and, within a short timeframe (two hours), registers a new device to their account. This behavior is indicative of the 'ARToken' persistence pattern, where an adversary uses a stolen session to bind a rogue device to the victim's account, potentially to mint a Primary Refresh Token (PRT) for persistent access.
Microsoft Sentinel (KQL)

