drop entra id auth log · parse fido2 + ms authenticator + tap usage
flags TAP issuance bursts · FIDO2 from new device · passwordless fallback to legacy auth
heuristic screener · export schema varies by portal/API version — not definitive proof