device, code, phishing, attacks, hotness, m365
ID: 80c22025-37ab-519e-957d-2a91d398d330
STIX ID: report--80c22025-37ab-519e-957d-2a91d398d330
Feed Name: TrustedSec blog
Device code phishing abuses the OAuth 2.0 device authorization grant (device code flow) by tricking victims to enter attacker‑generated device codes at the legitimate Microsoft device login page, yielding attacker-held refresh tokens that bypass MFA and conditional access controls; the report details the attack steps, example requests/responses and tooling, detection queries and log signals (Entra sign‑in logs, Unified Audit Log), and remediation guidance (block device code flow via Conditional Access, revoke refresh tokens, remove mailbox rules).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
