How to Spot and Stop Rogue Device Joins
ID: 42076fff-a4bf-59f3-b874-a6dd9f7087dc
STIX ID: report--42076fff-a4bf-59f3-b874-a6dd9f7087dc
Feed Name: Wiz Blog
This report describes a common attack playbook where attackers use device-code phishing to obtain authorization and abuse Entra ID’s Device Registration Service to register rogue devices (often using predictable or AI-generated device names and User-Agent strings), allowing access to Microsoft 365 resources and persistence; it provides observed IOCs, detection strategies (naming-anomaly and sequential correlation), KQL hunting queries, and recommended hardening (MFA for device registration) along with Wiz Defend detection rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
