| a user running azure cli, azure powershell, vs code, graph cli, or visual studio on a jump host, cloud shell, or vpn egress that differs from the workstation's windows sign-in ip can match if that activity still presents a compliant or managed workstation deviceid. validate whether the graph client ran on the enrolled device before treating the event as cookie theft. | |