Analytics BIOC
Informational
✕
Azure device code authentication flow used
An Azure AD login was performed with device code flow.
- Module:
- Identity Analytics
- Data source:
- Azure Audit Log
ATT&CK tactics: Defense Evasion (TA0005) Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098) Use Alternate Authentication Material (T1550)
Attacker's goals:
An attacker may use a device to access resources in the tenant using an access token from device code authentication flows.
Investigative actions:
Check what devices are listed with the logged-in user. Check if the account is authorized to use such devices to access resources. Check for possible logins from the device. Follow further actions done by the account and device.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
3 variations:
- Suspicious Azure device code authentication flow used by an Azure AD privileged user Medium (parent: Informational)
- Suspicious Azure device code authentication flow used Low (parent: Informational)
- Azure device code authentication flow used by an Azure AD privileged user Low (parent: Informational)