#Blogger, #ediscovery and #M365 Consultant, #trainer, social media enthusiast, husband, amateur photographer, child abuse survivor. Views are mine, no one else wants them. ;-) he/him/his
Turns coffee into infrastructure code. Speaker, husband, dad. Linux & vim lover, podman and K8s User. More ops than dev. More and more IT security. Opinions are my own. Mixed Toots in german and english. "Only Dead Fish Go With The Flow" Stoeps' law: "If a process contains Excel, the process is broken." #stoepslaw
🎯 Threat Intelligence
Device code flow phishing continues to surface as an initial access technique in M365 and BEC incident response engagements handled by TrustedSec. The technique bypasses both user suspicion and several Conditional Access patterns organizations depend on.
Legitimate Device Code Flow
The OAuth 2.0 device authorization grant (RFC 8628) exists for devices that cannot host a browser, such as smart TVs, CLI tools, IoT hardware, and printers. Microsoft implements it in Entra ID for Azure CLI, the kubectl Entra plugin, and device enrollment flows.
The flow runs in six steps:
- The client requests a device code from Entra ID, specifying resource and scopes
- Entra returns a device_code, a human-readable user_code, the verification URL at microsoft.com/devicelogin, and a ~15 minute TTL
- The client displays the code and URL to the user
- The user opens the URL on a second device, enters the code, signs in, and consents
- The client polls the token endpoint with the device_code
- Entra issues an access_token and refresh_token to the polling client
The Attack
The critical gap: nothing in the protocol binds the party who initiates the flow to the party who completes authentication. An attacker initiates the flow, obtains a device code, then social-engineers a victim into entering that code on the real microsoft.com/devicelogin. The victim signs in, approves legitimate MFA prompts, and consents. Tokens are issued to the attacker's polling session.
The lure typically mimics a legitimate login request, often claiming a shared document requires authentication. The link points to the actual Microsoft domain, not a lookalike. Every element the victim interacts with is genuine Microsoft infrastructure.
Why It Works
MFA is not technically bypassed. The victim completes it legitimately, and the policy is satisfied. Conditional Access policies see authentication originating from a legitimate Microsoft endpoint, not attacker-controlled redirect infrastructure. The only forensic artifact is an OAuth token issued to a session the attacker controls. The 15-minute device code window provides ample time for social engineering delivery.
Detection
Monitor Entra ID sign-in logs for the authentication method "Device Code Flow." Correlate with user behavior baselines to identify unexpected usage. Tokens granted via this method from unusual locations or for atypical applications warrant investigation. Consider restricting device code flow entirely in environments that do not require it.
The source describes the mechanism from lab-tenant reproductions. No specific IOCs from live incidents are provided.
🔹 devicecodephishing #M365 #OAuth #ConditionalAccess #ThreatIntelligence
#Blogger, #ediscovery and #M365 Consultant, #trainer, social media enthusiast, husband, amateur photographer, child abuse survivor. Views are mine, no one else wants them. ;-) he/him/his
End-to-end Cybersecurity consulting team leading the industry, supporting organizations, and giving back. #Hacktheplanet Blogs, news, webinars, and tools! This account is a replica from Twitter. Its author can't see your replies. If you find this service useful, please consider supporting us via our Patreon.
Civil servant from the Netherlands, fascinated by innovative technologies and how they can improve society. Also interested in geopolitics and international affairs. All opinions expressed are purely personal and do not represent the opinion of my employer or anyone else. #digitalgovernment #innovation #digitaltransformation #AI #technology #tfr tootfinder #ICT #IT #fedi22 #geopolitics #AcICT Signal: erikjonker.09
#Blogger, #ediscovery and #M365 Consultant, #trainer, social media enthusiast, husband, amateur photographer, child abuse survivor. Views are mine, no one else wants them. ;-) he/him/his
Words published here do not necessarily reflect views of my employer or any other organization I am affiliated with. Research and analysis about malware, network forensics, and the intersection of crime with anything that electrons or photons flow through. Board member of World Cyber Health, the parent organization behind Malware Village and the NO-HAVOC project. Docent of obsolete technology at @mediaarchaeologylab Executive director, Elect More Hackers: electmorehackers.com "By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges." -- Cory Doctorow
Responsible innovation means pursuing improvements that benefit both the inventor and society | Born in 1963 at 320 ppm CO2 #compliance #responsibleinnovation #datenschutz #privacy #informationssicherheit #informationsecurity #esg #privacyofficers #fedi22 #tfr
You've seen all posts