Press enter or click to view image in full size
The most convincing Microsoft phishing attack yet. Learn how attackers abuse Microsoft’s trusted device authentication process, obtain access tokens instead of passwords, and why traditional MFA awareness alone is no longer enough.
Have You Ever Come Across a Website Like This Below Screenshot? No fake Microsoft login pages. No stealing of passwords. No cloned authentication forms. No obvious browser warnings. Yes that’s device code phishing
Press enter or click to view image in full size
It carries Microsoft’s branding, displays a verification code, and instructs users to continue their sign-in using the official Microsoft Device Login page. Unlike traditional phishing websites, there are no fake Microsoft login forms, no requests for your password, and no obvious signs that something is wrong.
So, it must be safe… right?
Not necessarily.
Device Code Phishing has become one of the most effective phishing techniques because it abuses Microsoft’s legitimate authentication workflow instead of attempting to steal usernames and passwords. Since users authenticate directly with Microsoft, many of the traditional warning signs associated with phishing are absent, making these attacks significantly more convincing.
In this article, the ThreatWatch360 team explains how Device Code Phishing works, why it is dangerous, and how attackers leverage this technique to gain unauthorized access to Microsoft 365 accounts without ever asking victims for their credentials.
Before understanding Device Code Phishing, it’s important to understand Device Code Authentication.
Microsoft introduced the Device Code Flow to allow devices with limited input capabilities, such as smart TVs, conference room devices, IoT devices, and command-line applications, to authenticate users.
Instead of entering credentials directly on the device, Microsoft generates a short verification code.
The user then visits Microsoft’s official Device Login page, enters the code, signs in with their Microsoft account, and authorizes the request.
The authenticated session is then linked back to the requesting application.
This workflow is completely legitimate and is widely used by Microsoft-supported applications.
Unfortunately, threat actors discovered they could abuse this authentication flow for phishing.
Unlike traditional phishing attacks, Device Code Phishing does not steal passwords.
Instead, it tricks victims into authorizing an attacker-controlled application using Microsoft’s own authentication infrastructure.
The result is that the attacker receives a valid Microsoft access token after the victim successfully authenticates.
Stage 1 — The Phishing Email
Press enter or click to view image in full size
The attack usually begins with a convincing phishing email.
In our demonstration, the victim receives an email claiming that Microsoft detected unusual sign-in activity and encourages them to secure their account immediately.
The email closely resembles legitimate Microsoft security notifications, making it difficult for many users to distinguish between genuine and malicious messages.
Instead of directing users to a fake Microsoft login page, the email redirects them to an attacker-controlled website.
This subtle difference is what makes Device Code Phishing particularly dangerous.
Stage 2 — The Fake Verification Portal
Press enter or click to view image in full size
After clicking the email link, the victim is presented with what appears to be a Microsoft verification portal.
The page displays:
Everything appears authentic.
Unlike credential phishing pages, this website never asks the user for their Microsoft username or password.
Instead, it simply instructs the user to authenticate through Microsoft itself.
This dramatically increases trust.
Stage 3 — Redirecting to Microsoft’s Official Login Page
Press enter or click to view image in full size
Clicking the verification button redirects the victim to Microsoft’s official Device Login page.
Notice the URL.
The browser clearly displays Microsoft’s legitimate domain: login.microsoftonline.com
This is not a fake login page.
This is Microsoft’s real authentication portal.
Since users are interacting directly with Microsoft, many security-conscious individuals believe the request is legitimate.
Stage 4 — Entering the Device Code
Press enter or click to view image in full size
The victim enters the code displayed on the phishing website into Microsoft’s official authentication page.
At this point, everything still appears normal.
The authentication process is entirely handled by Microsoft.
No passwords have been stolen.
No fake login page has been displayed.
Yet the attacker is already one step closer to gaining access.
Stage 5 — Microsoft Requests Account Authorization
Press enter or click to view image in full size
Once the code is accepted, Microsoft asks the victim to select the account they wish to authorize.
Again, this occurs entirely on Microsoft’s legitimate infrastructure.
Nothing appears suspicious.
Most users assume they are completing a routine Microsoft verification process.
Stage 6 — Granting Access
Press enter or click to view image in full size
Microsoft now asks the user to confirm the authentication request.
Join Medium for free to get updates from this writer.
The victim clicks Continue, believing they are protecting or verifying their Microsoft account.
Instead, they are unknowingly authorizing an attacker-controlled application.
Stage 7 — Authentication Complete
Press enter or click to view image in full size
Microsoft confirms that authentication has completed successfully.
From the victim’s perspective, everything appears perfectly normal.
There are no error messages.
No warnings.
No indication that their Microsoft session has now been shared with someone else.
Press enter or click to view image in full size
Behind the scenes, the attacker’s phishing infrastructure immediately receives the Microsoft access token generated during the authentication process.
Unlike traditional phishing attacks, the attacker never needed the victim’s password.
Instead, they now possess a valid Microsoft authentication token issued directly by Microsoft.
Stage 9 — Accessing Microsoft Resources
Press enter or click to view image in full size
Using the captured token, the attacker can begin interacting with Microsoft Graph APIs according to the permissions granted during authentication.
Depending on the permissions available, this may allow access to resources such as:
In our demonstration, the captured token is used to search mailbox content, illustrating how quickly authenticated access can be abused after the victim completes the authorization process.
Traditional phishing relies on fake login pages.
Device Code Phishing is different.
The victim authenticates directly with Microsoft.
Every important step occurs on Microsoft’s legitimate domain.
This removes many of the indicators users have been trained to recognize.
There are:
Instead, attackers exploit the trust users place in Microsoft’s legitimate authentication process.
Modern phishing campaigns are evolving beyond simple credential theft. By abusing legitimate authentication workflows, attackers can obtain valid access tokens without ever knowing a user’s password. This makes Device Code Phishing particularly attractive because it blends legitimate authentication with social engineering. Organizations relying solely on user awareness around fake login pages may find these attacks significantly more difficult to detect.
Although Device Code Authentication is a legitimate Microsoft feature, there are several ways users can protect themselves from Device Code Phishing attacks.
If you receive an unexpected email asking you to verify your Microsoft account using a device code, stop and verify the request before proceeding.
Ask yourself:
If the answer is no, do not continue.
Threat actors frequently use messages about unusual sign-in activity, account suspension, or urgent verification to pressure victims into acting quickly.
Regularly review the applications connected to your Microsoft account and remove any unfamiliar or unnecessary authorizations.
If you believe you accidentally completed a Device Code Phishing request:
Acting quickly can significantly reduce the impact of token-based attacks.
Device Code Phishing demonstrates that modern phishing attacks no longer need to steal passwords to be successful.
By abusing Microsoft’s legitimate Device Code authentication workflow, attackers can trick users into authorizing malicious applications while every authentication step takes place on Microsoft’s official infrastructure.
This makes the attack highly convincing, difficult for users to recognize, and increasingly relevant in modern phishing campaigns.
Understanding how this technique works is the first step toward recognizing suspicious authentication requests and preventing unauthorized access to Microsoft 365 environments.
As attackers continue to shift toward token-based authentication abuse, user awareness remains one of the most effective defenses against these evolving phishing techniques.