Microsoft Entra ID (Azure AD) detected a token replay attack against taylor.kim@acme-corp.com at 10:35. An attacker obtained a valid session token (likely via AiTM phishing) and replayed it from IP 104.21.88.12 (Cloudflare proxy · Netherlands). The legitimate user was simultaneously authenticated from her known MacBook in London. Microsoft Identity Protection scored the sign-in as 'High Risk' (93% confidence) and Conditional Access automatically blocked the suspicious session and forced password reset. The phishing email that delivered the AiTM kit has been quarantined from the mail gateway.