Device Code Phishing and Persistent OAuth Consent: 2026 APT Tradecraft in Entra ID
A defender-focused analysis of how APT29-aligned and Storm-2372-style intrusion sets are abusing device authorization grants and long-lived OAuth consent in Entra ID through 2026 — what to detect, what to revoke, and where it maps to 800-53.