Trend Micro
Read post

Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass

Device code phishing abuses the OAuth 2.0 device authorization grant — a legitimate flow designed for input-limited devices like smart TVs — to bypass MFA without stealing passwords. The attacker initiates a real Microsoft device-code request, tricks a victim into approving it on the genuine Microsoft sign-in page, and receives the resulting tokens. A real-world Microsoft 365 case is detailed: attackers built trust via multi-message conversations, used Google Sites and open redirectors to evade URL filtering, and after token capture registered rogue devices, created hidden inbox rules, and launched further phishing campaigns entirely from the cloud. Defenses include blocking the device-code OAuth flow via Conditional Access where not needed, restricting device registration, enforcing named-location policies, enabling Continuous Access Evaluation, and training users to treat unexpected code-entry requests as red flags. Detection queries for Microsoft Entra ID sign-in logs and MITRE ATT&CK mappings are provided, along with IOCs.

    #microsoft#authentication#phishing#oauth
Jul 22•9m read time•From trendmicro.com
Post cover image
72 Impressions
Trend Micro's image
Trend Micro

Trend Micro Blog offers insights, analysis, and updates on cybersecurity threats, trends, and best p...

75 Followers

•

72 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard