Analytics BIOC Informational

Azure device code authentication flow used

An Azure AD login was performed with device code flow.

Module:
Identity Analytics
Data source:
Azure Audit Log
ATT&CK tactics: Defense Evasion (TA0005) Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098) Use Alternate Authentication Material (T1550)
Attacker's goals:

An attacker may use a device to access resources in the tenant using an access token from device code authentication flows.

Investigative actions:

Check what devices are listed with the logged-in user. Check if the account is authorized to use such devices to access resources. Check for possible logins from the device. Follow further actions done by the account and device.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • Suspicious Azure device code authentication flow used by an Azure AD privileged user Medium (parent: Informational)
  • Suspicious Azure device code authentication flow used Low (parent: Informational)
  • Azure device code authentication flow used by an Azure AD privileged user Low (parent: Informational)