2026 Critical Enterprise Intrusion Chain Detection: New Device Registration Immediately Following Non-Interactive Token Reuse

This rule detects a correlation between a successful non-interactive authentication event (e.g., token-based sign-in) and a subsequent device registration event performed by the same user identity within a short time window. This sequence is a known pattern for attackers seeking to register an adversary-controlled device against a compromised account to establish durable persistence and potentially bypass conditional access policies (PRT persistence).