Entra Sign-In via OAuth Device Code Flow (Possible ARToken Phishing)
Detects successful Entra ID sign-in events that utilize the OAuth 2.0 device authorization grant (device code) flow. This authentication mechanism is frequently abused by attackers to perform device code phishing (e.g., ARToken attacks), where victims are tricked into entering a malicious user code on a legitimate Microsoft login portal to facilitate token theft.
Microsoft Sentinel (KQL)

