GhostCode abuses Microsoft's device authorization flow to obtain tokens and register attacker hardware inside a victim tenant.