Glossary
Device code phishing
Phishing that abuses the OAuth device code flow: the victim enters an attacker-supplied code on Microsoft's device login page and the attacker receives the tokens.
Device code phishing abuses the OAuth 2.0 device authorization grant, designed for devices without a keyboard. The attacker starts a device code sign-in, sends the victim the code with a pretext (a meeting invitation, a document), and the victim enters it on Microsoft's legitimate device login page and completes MFA. The tokens are issued to the attacker's session.
Microsoft documented a large campaign using this technique, by an actor it tracks as Storm-2372, in February 2025. In Entra sign-in logs such sign-ins show Authentication Protocol = deviceCode, and later tokens carry originalTransferMethod = deviceCodeFlow. Microsoft recommends blocking the device code flow with a Conditional Access authentication flows policy wherever it is not needed.