A Scam That Bypasses the Usual Defences
Microsoft has flagged a growing wave of attacks using a technique called device code phishing. Unlike traditional phishing, which tries to steal your password via a fake login page, device code phishing uses a genuine Microsoft login screen. There are no suspicious URLs, no fake forms, and everything looks entirely normal. Yet the result is that an attacker gains full access to your Microsoft account without ever knowing your password.
It is catching businesses off guard precisely because the usual warning signs are absent.
How Device Code Phishing Works
The attack typically begins with a convincing email, often appearing to come from HR or a colleague, inviting you to a Microsoft Teams meeting. When you click the link, you are taken to a real Microsoft login screen and asked to enter a short device code that was included in the email. It feels routine because the page is genuine.
The problem is that by entering that code, you are not logging yourself in. You are logging the attacker into your Microsoft account on their device. The login flow is legitimate, which means multi-factor authentication can be bypassed. Once inside, attackers can read emails, access files, and impersonate you to target colleagues. They also capture session tokens, which keep them logged in even after a password change.
How to Protect Your Business
Train your team to question device code requests
Staff should understand that entering a device code into a login screen is never a normal part of joining a meeting or responding to a calendar invite. Any email requesting this should be treated as suspicious and reported. If in doubt, verify through a separate channel before taking any action.
Disable device code authentication if you do not need it
If your business does not use scenarios that genuinely require device code login flows, this method can be disabled entirely in your Microsoft tenant. Your IT support provider can configure this, removing the attack vector completely.
Implement conditional access policies
Conditional access rules restrict logins to trusted locations or registered devices. This limits the ability of an attacker to authenticate from an unfamiliar device or location, even if they have obtained a valid session token.
Monitor for unusual login activity
Continuous monitoring of login events, including logins from new devices or unusual locations, helps catch account compromises early. Blowfish Technology can configure alerting and monitoring as part of a managed security service.
Support Across the North West
Blowfish Technology helps businesses across the North West audit their Microsoft security configuration and put the right protections in place. We cover IT Support Manchester, IT Support Liverpool, and IT Support Chester.
The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.