For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure device code authentication flow used

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Azure Audit Log

Detection Modules

Identity Analytics

ATT&CK Tactic

Persistence (TA0003), Lateral Movement (TA0008)

ATT&CK Technique

Account Manipulation (T1098), Use Alternate Authentication Material (T1550)

Severity

Informational

Description

An Azure AD login was performed with device code flow.

Attacker's Goals

  • An attacker may use a device to access resources in the tenant using an access token from device code authentication flows.

Investigative actions

  • Check what devices are listed with the logged-in user.

  • Check if the account is authorized to use such devices to access resources.

  • Check for possible logins from the device.

  • Follow further actions done by the account and device.

Variations

Suspicious Azure device code authentication flow used by an Azure AD privileged user

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Lateral Movement (TA0008)

ATT&CK Technique

Account Manipulation (T1098), Use Alternate Authentication Material (T1550)

Severity

Medium

Description

An Azure AD login was performed with device code flow.

Attacker's Goals

  • An attacker may use a device to access resources in the tenant using an access token from device code authentication flows.

Investigative actions

  • Check what devices are listed with the logged-in user.

  • Check if the account is authorized to use such devices to access resources.

  • Check for possible logins from the device.

  • Follow further actions done by the account and device.

Suspicious Azure device code authentication flow used

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Lateral Movement (TA0008)

ATT&CK Technique

Account Manipulation (T1098), Use Alternate Authentication Material (T1550)

Severity

Low

Description

An Azure AD login was performed with device code flow.

Attacker's Goals

  • An attacker may use a device to access resources in the tenant using an access token from device code authentication flows.

Investigative actions

  • Check what devices are listed with the logged-in user.

  • Check if the account is authorized to use such devices to access resources.

  • Check for possible logins from the device.

  • Follow further actions done by the account and device.

Azure device code authentication flow used by an Azure AD privileged user

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Lateral Movement (TA0008)

ATT&CK Technique

Account Manipulation (T1098), Use Alternate Authentication Material (T1550)

Severity

Low

Description

An Azure AD login was performed with device code flow.

Attacker's Goals

  • An attacker may use a device to access resources in the tenant using an access token from device code authentication flows.

Investigative actions

  • Check what devices are listed with the logged-in user.

  • Check if the account is authorized to use such devices to access resources.

  • Check for possible logins from the device.

  • Follow further actions done by the account and device.

Was this helpful?