logo

Revisiting sound guidance: Countering the heightened threat of device code phishing

ID: 55c84867-3a42-5b42-bb2e-4785db6039a7

STIX ID: report--55c84867-3a42-5b42-bb2e-4785db6039a7

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2026-04-17

Date Updated: 2026-04-27

...
...

The report warns that attackers are abusing Microsoft’s device code authentication—used for kiosks/shared devices—to phish users into handing over device codes that yield valid session tokens, thereby bypassing passwords and MFA and achieving persistent account access. It recommends disabling or tightly restricting device code flow where not required and explicitly revoking sessions (not just resetting passwords) when an account is compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.