logo

device, code, phishing, attacks, hotness, m365

ID: 80c22025-37ab-519e-957d-2a91d398d330

STIX ID: report--80c22025-37ab-519e-957d-2a91d398d330

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2026-07-21

Date Updated: 2026-07-22

...
...

Device code phishing abuses the OAuth 2.0 device authorization grant (device code flow) by tricking victims to enter attacker‑generated device codes at the legitimate Microsoft device login page, yielding attacker-held refresh tokens that bypass MFA and conditional access controls; the report details the attack steps, example requests/responses and tooling, detection queries and log signals (Entra sign‑in logs, Unified Audit Log), and remediation guidance (block device code flow via Conditional Access, revoke refresh tokens, remove mailbox rules).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.