Session token replay from unmanaged device after prior managed sign-in

Detects potential session hijacking where an Entra ID session is reused by a non-managed/non-compliant device from a different IP and country shortly after an initial authentication from a managed device. This pattern is consistent with infostealer malware stealing session tokens and replaying them on attacker-controlled infrastructure to bypass MFA.