All systems operational · Ormskirk, North West England

Criminals Can Access Your Accounts Without Your Password

Device code phishing uses genuine Microsoft login pages to gain access to your accounts without needing your password. Microsoft has flagged a rising wave of these attacks. Here is what your business needs to know.

A Scam That Bypasses the Usual Defences

Microsoft has flagged a growing wave of attacks using a technique called device code phishing. Unlike traditional phishing, which tries to steal your password via a fake login page, device code phishing uses a genuine Microsoft login screen. There are no suspicious URLs, no fake forms, and everything looks entirely normal. Yet the result is that an attacker gains full access to your Microsoft account without ever knowing your password.

It is catching businesses off guard precisely because the usual warning signs are absent.

How Device Code Phishing Works

The attack typically begins with a convincing email, often appearing to come from HR or a colleague, inviting you to a Microsoft Teams meeting. When you click the link, you are taken to a real Microsoft login screen and asked to enter a short device code that was included in the email. It feels routine because the page is genuine.

The problem is that by entering that code, you are not logging yourself in. You are logging the attacker into your Microsoft account on their device. The login flow is legitimate, which means multi-factor authentication can be bypassed. Once inside, attackers can read emails, access files, and impersonate you to target colleagues. They also capture session tokens, which keep them logged in even after a password change.

Key point: You will never be asked to enter a device code to join a Teams meeting or respond to a routine invitation. If an email asks you to do this, do not proceed.

How to Protect Your Business

Train your team to question device code requests

Staff should understand that entering a device code into a login screen is never a normal part of joining a meeting or responding to a calendar invite. Any email requesting this should be treated as suspicious and reported. If in doubt, verify through a separate channel before taking any action.

Disable device code authentication if you do not need it

If your business does not use scenarios that genuinely require device code login flows, this method can be disabled entirely in your Microsoft tenant. Your IT support provider can configure this, removing the attack vector completely.

Implement conditional access policies

Conditional access rules restrict logins to trusted locations or registered devices. This limits the ability of an attacker to authenticate from an unfamiliar device or location, even if they have obtained a valid session token.

Monitor for unusual login activity

Continuous monitoring of login events, including logins from new devices or unusual locations, helps catch account compromises early. Blowfish Technology can configure alerting and monitoring as part of a managed security service.

Support Across the North West

Blowfish Technology helps businesses across the North West audit their Microsoft security configuration and put the right protections in place. We cover IT Support Manchester, IT Support Liverpool, and IT Support Chester.

B
Blowfish Technology

The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.