Microsoft Device Code Flow Abuse Creates a New Risk for M365 Accounts
Overview
A new phishing campaign targeting Microsoft 365 accounts abuses the legitimate Microsoft device code flow to trick users into approving access to their accounts. Instead of sending victims to a fake password page, attackers use the real Microsoft login process and convince the user to enter a code controlled by the attacker.
This makes the attack harder to recognize. The user sees a legitimate Microsoft page, completes an expected authentication process, and may not realize they are approving a session initiated by the attacker.
According to public reporting from July 2026, the new campaign uses a tooling layer called DEBULL and shows similarities to previously documented device code phishing techniques. Microsoft documented Storm-2372 in 2025, where threat actors used lures resembling communication apps such as WhatsApp, Signal, and Microsoft Teams to convince users to enter device codes.
What Device Code Flow Is
Device code flow is a legitimate OAuth 2.0 authentication mechanism. It was designed for devices that cannot easily support username and password entry, such as smart TVs, printers, shared devices, or endpoints with limited input capability.
The normal process looks like this:
- the device displays a short code;
- the user opens the Microsoft device login page on another device;
- the user enters the code;
- the user completes authentication;
- the device receives access.
In an abuse scenario, the attacker initiates this process instead of a legitimate device. They then send the code to the victim through a phishing lure. When the user enters the code on the real Microsoft page, they unknowingly approve an attacker-controlled session.
How the Attack Works
Device code phishing does not rely on a classic fake login page. That is the main difference from many traditional phishing campaigns.
A typical scenario includes:
- the user receives an email or message using a collaboration, payment, document, or shared-folder pretext;
- the link leads to intermediary infrastructure or a compromised website;
- backend tooling generates a Microsoft device code;
- the user is instructed to open the legitimate Microsoft device login page;
- the user enters the code and completes authentication;
- Microsoft issues tokens to the session initiated by the attacker;
- the attacker uses the tokens to access the M365 account.
This technique works because the attack runs through a trusted authentication process. The user may see a real Microsoft domain and real MFA steps, but the session context is controlled by the attacker.
Why This Matters
Device code phishing shifts the focus from password theft to authorization token theft. This is an important change for Microsoft 365 security.
If the attacker obtains valid tokens, they may access:
- Outlook mailboxes;
- Teams communication;
- OneDrive files;
- SharePoint documents;
- calendars and contacts;
- internal correspondence;
- sensitive attachments;
- business email compromise workflows;
- data available through Microsoft Graph API.
This can lead to account takeover, fraud, Business Email Compromise (BEC), internal phishing, document exfiltration, and lateral movement toward other accounts or services.
Why Standard MFA Is Not Enough
In device code phishing, the user may complete MFA successfully. The problem is that they are doing it for a session they do not fully understand.
This means MFA alone is not sufficient protection. Organizations need to control when, where, and for which applications device code flow is allowed.
Microsoft recommends controlling device code flow through Conditional Access policies, because this authentication flow may be used to access corporate resources from unmanaged devices.
PhaaS and the Industrialization of Identity Attacks
The broader risk is that device code phishing is no longer only a technique used by individual groups. In 2026, public analysis describes the growth of phishing-as-a-service kits supporting device code attacks, dynamic code generation, and post-authentication workflows. Microsoft also reported an AI-enabled device code phishing campaign where dynamic code generation helped compromise organizational accounts at scale.
This lowers the barrier for attackers. Operators no longer need to build the full infrastructure themselves. They can use tooling that manages lure pages, token capture, email access, SharePoint exfiltration, and BEC workflows.
When authentication abuse is packaged as a service, defense must become operational: logs, policies, token controls, visibility, and rapid response.
Recommended Actions
Organizations using Microsoft 365 should treat device code phishing as an identity security risk, not only an email phishing issue.
Priority actions include:
- restrict or block device code flow through Microsoft Entra Conditional Access where not required;
- define which applications and devices are allowed to use this flow;
- monitor sign-in logs for device code authentication events;
- investigate unusual token activity, unfamiliar devices, and suspicious locations;
- monitor Microsoft Graph API activity that does not match normal user behavior;
- terminate suspicious sessions and revoke refresh tokens;
- restrict sensitive resource access to compliant or managed devices;
- train users not to enter device codes received by email, chat, or documents;
- monitor for internal phishing from already compromised accounts;
- check mailbox rules, forwarding settings, and OAuth grants after suspected compromise.
If abuse is confirmed, password reset alone is not enough. Sessions must be terminated, tokens revoked, and post-authentication activity reviewed.
DIAMATIX Perspective
Device code phishing shows why identity security can no longer be viewed only as a password policy and MFA problem.
In this scenario, the attacker does not try to break the Microsoft login process. They use a legitimate authentication flow in a way that misleads the user and transfers control over the session.
This changes how organizations should think about protection:
- which authentication flows are allowed;
- which devices are trusted;
- how tokens are monitored;
- how anomalies are detected after successful login;
- how suspicious access is contained;
- how access to Outlook, Teams, OneDrive, and SharePoint is controlled.
Protection must cover the full identity lifecycle: login, device, token, session, application access, and post-authentication behavior.
CISO Analysis
From a CISO perspective, device code phishing is a risk to identities, tokens, and cloud data.
Key questions include:
- Is device code flow enabled in our Microsoft 365 environment?
- Is it actually required for our users and applications?
- Can we restrict it through Conditional Access?
- Can the SOC see device code authentication events?
- Are tokens being used from unusual devices or locations?
- Do we have a process to quickly revoke tokens and terminate sessions?
- Do we monitor mailbox rules, forwarding, and SharePoint downloads after suspicious sign-ins?
- Can we connect a phishing email to follow-on token activity?
Successful authentication does not always mean legitimate access. In device code phishing, the question is not only who signed in, but who controlled the session.
What This Means for Your Environment
- This type of attack relies on a legitimate Microsoft authentication flow that the user approves without realizing the session was initiated by the attacker.
- Detection depends on visibility into device code flow events, token usage, sign-in behavior, Microsoft Graph activity, mailbox changes, and cloud access patterns.
- Response requires Conditional Access controls, session termination, token revocation, post-compromise mailbox review, and monitoring of post-login activity.
Do you know whether device code flow is enabled in your Microsoft 365 environment?
Can you detect suspicious token activity after an apparently legitimate authentication?
See how identity-focused attacks are investigated and handled in real operational environments.
Check whether your Microsoft 365 environment is exposed to device code phishing
Device code phishing abuses a legitimate Microsoft authentication flow to obtain tokens and account access without using a classic fake login page.
DIAMATIX can help you assess:
- whether device code flow is enabled in your environment;
- which Conditional Access policies are active;
- whether token or sign-in activity shows anomalies;
- whether Microsoft 365 logs provide enough visibility for SOC analysis;
- how sessions and tokens are revoked when compromise is suspected.
Request a Microsoft 365 identity risk review with DIAMATIX.
Trusted · Innovative · Vigilant
Sources
- Microsoft Security. Storm-2372 conducts device code phishing campaign.
- Microsoft Security. Inside an AI-enabled device code phishing campaign.
- Microsoft Learn. Conditional Access: Authentication flows.
- Push Security. Analyzing the rise in device code phishing attacks in 2026.
- Cisco Talos. ARToken and EvilTokens device code phishing analysis.
This article is based on publicly available technical information and analysis as of July 2026.






