Azure device code authentication flow used
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Azure Audit Log
Detection Modules
Identity Analytics
ATT&CK Tactic
Persistence (TA0003), Lateral Movement (TA0008)
ATT&CK Technique
Account Manipulation (T1098), Use Alternate Authentication Material (T1550)
Severity
Informational
Description
An Azure AD login was performed with device code flow.
Attacker's Goals
An attacker may use a device to access resources in the tenant using an access token from device code authentication flows.
Investigative actions
Check what devices are listed with the logged-in user.
Check if the account is authorized to use such devices to access resources.
Check for possible logins from the device.
Follow further actions done by the account and device.
Variations
Was this helpful?
