2026 Critical Cloud Identity Detection: Primary Refresh Token or Device Code Phishing Sign-In Anomaly

Detects a potential Primary Refresh Token (PRT) or device code phishing attack by identifying a two-step authentication sequence: first, a successful user sign-in via device code flow, followed shortly by a subsequent sign-in from a different, unmanaged, or untrusted device. This behavioral pattern often indicates an adversary using stolen device code session data to authenticate a new device session.