A fake meeting invite, a real Microsoft sign-in page, and a code the victim types in themselves: that is all it takes to hand an attacker a signed-in Microsoft 365 session, with no password stolen and the victim's own MFA satisfied. Cybereinforce blocks that sign-in step in the browser, by default, for every organisation.
Nothing in this attack is fake except the story. Every page the victim signs in on is genuine Microsoft.
A message arrives by email, Teams chat, SMS or a QR code: a meeting invitation, a shared document, a security review. It comes with a short code and an instruction to "confirm your device".
The victim opens Microsoft's own device sign-in page and types the code. The address bar shows a real Microsoft domain, so every habit says it is safe.
The code was generated by the attacker. When the victim finishes signing in and approves MFA, Microsoft issues the session tokens to the attacker, not to the victim's device.
With those tokens the attacker reads mail, Teams and SharePoint, and can register their own device in your tenant so that later activity looks like it comes from a known machine.
Most attacks leave something that looks wrong. This one is built to look right, which is exactly what makes analysts trust it.
| Domain | login.microsoftonline.com |
| MFA | satisfied |
| Device ID | present |
| Device name | present |
| Device trust type | Azure AD registered |
Illustrative. Real values are tenant-specific.
Device code phishing is documented by Microsoft and by other security vendors as an active technique used by multiple threat actors, and it is easy to run at scale. Detecting it after the fact is hard. Preventing the step that makes it possible is not.
We do not try to out-guess the lure. Lures change every day. The device-code sign-in page does not.
The device-code sign-in URL is blocked by the platform for every Cybereinforce customer. There is nothing to configure and no rule to remember to add.
Email, Teams, SMS, QR code or a phone call: whichever way the victim reaches the sign-in page, the browser stops there.
The protection is applied by the platform, it does not use up your rule allowance, and it reaches every organisation without any setup.
Pages that imitate the Microsoft device login on a different domain are caught by our brand-lookalike and phishing-lure detections, including newly registered domains.
Pages that copy the device-login flow on look-alike domains are recognised by what they ask the victim to do, not only by where they are hosted.
Blocked attempts are logged with the reason and available to your SOC, so a lure that reached your staff becomes a visible, investigable event.
Start a trial and see the block page for yourself, or talk to us about how it fits your Microsoft 365 environment.
Start Free Trial Threat Intelligence & Detections Contact us* Applies to browsers enrolled in Cybereinforce, where the device-code sign-in page is blocked by default. Organisations that rely on legitimate device-code sign-ins can permit them for their own organisation through the Whitelist. The Microsoft interface shown is an illustrative capture; the lure is a demonstration example, not a real message.