Device code phishing – the misuse of OAuth 2.0’s device authorization grant to acquire access tokens – has surged from a specialized red-hat tactic into an industrial-scale threat within just six months. Originally designed for input-limited devices like smart TVs, printers, and more, this login flow has been adopted by a broad array of apps and use cases it was never intended for – most commonly CLI logins. Researchers initially disclosed this attack vector in 2020, but it wasn't until 2024 that nation-state actors like Storm-2372 began deploying it in the wild.
Users interact with legitimate provider URLs, offering enhanced security without requiring additional steps.
Additionally, while these policies help protect against unauthorized access within the Microsoft ecosystem, they do not offer sufficient protection against phishing attacks targeting external platforms like GitHub or AWS, where equivalent conditional access controls might not exist. For a detailed technical breakdown, including a side-by-side demonstration of what the victim and attacker see during a device code phishing attack, the escalation chain from stolen tokens to full SSO-level access, and defensive options available, watch the webinar. They also gain visibility and manage AI tool usage across their workforce, harden identities by identifying credential reuse, SSO gaps, and shadow IT, and support data loss and insider investigations with browser-layer telemetry that other tools can't see.












