RFC 8628 device code authentication flow abuse detection
Detects anomalous device-authorization-grant (RFC 8628) activity indicative of device-code phishing attacks (e.g., Tycoon2FA). The rule identifies user accounts exhibiting a rapid succession of 'authorization_pending' (70016) status polling attempts followed by a successful token issuance (0), constrained to a short time window and excluding known first-party Microsoft CLI/dev-tool applications.
Microsoft Sentinel (KQL)

