Skip to content

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Microsoft 365, Microsoft Entra ID, Exchange Online and Microsoft Purview are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.

Glossary

Device code phishing

Phishing that abuses the OAuth device code flow: the victim enters an attacker-supplied code on Microsoft's device login page and the attacker receives the tokens.

Device code phishing abuses the OAuth 2.0 device authorization grant, designed for devices without a keyboard. The attacker starts a device code sign-in, sends the victim the code with a pretext (a meeting invitation, a document), and the victim enters it on Microsoft's legitimate device login page and completes MFA. The tokens are issued to the attacker's session.

Microsoft documented a large campaign using this technique, by an actor it tracks as Storm-2372, in February 2025. In Entra sign-in logs such sign-ins show Authentication Protocol = deviceCode, and later tokens carry originalTransferMethod = deviceCodeFlow. Microsoft recommends blocking the device code flow with a Conditional Access authentication flows policy wherever it is not needed.

See Entra ID sign-in logs analysis.