CI Resource Center
Helping Small Businesses Stay Secure and Productive
🚨 Security Alert Security πŸ†• New
🚨
SECURITY ALERT
Active Threat Affecting Small Businesses
Threat Level HIGH

Device Code Phishing: A New Microsoft 365 Scam That Can Bypass Password Theft

πŸ•’ 2 min read Updated July 22, 2026

Cybercriminals are increasingly using a technique called Device Code Phishing to gain access to Microsoft 365 accounts. Unlike traditional phishing attacks, this method does not steal your password. Instead, it tricks users into approving a legitimate Microsoft sign-in request, giving attackers access to email, files, and other Microsoft 365 services.

🚨 Security Alert


Why This Matters

Most businesses have improved their security by enabling Multi-Factor Authentication (MFA).

Unfortunately, attackers have adapted.

Instead of trying to steal passwords, they now try to convince users to approve a legitimate Microsoft sign-in request that grants access to the attacker’s device.

Because the sign-in occurs through Microsoft’s own systems, everything can appear completely legitimate.


How the Scam Works

An employee receives an email or Teams message claiming they need to:

  • Join a meeting
  • Open a shared document
  • Verify their Microsoft account
  • Activate a collaboration tool

The message directs them to Microsoft’s legitimate Device Login page.

They enter a short code provided by the attacker.

The employee signs in with Microsoft 365.

They approve the MFA request.

The attacker is now signed in.

No password was stolen.

No malware was installed.

The attacker simply convinced the employee to approve their own access.


Warning Signs

Be suspicious if you are asked to:

  • Visit microsoft.com/devicelogin
  • Enter a device code that someone else provided
  • Approve an unexpected Microsoft sign-in
  • Authenticate for a meeting or collaboration request you didn’t initiate

If you weren’t expecting it, stop.


What You Should Do

If you receive an unexpected device code request:

  • Do not enter the code.
  • Do not approve the MFA request.
  • Report the message to your IT department.
  • Change your Microsoft 365 password if you believe you completed the request.

Why This Attack Is Different

Traditional phishing tries to steal your password.

Device Code Phishing uses Microsoft’s own authentication process.

That makes the attack much harder to recognize because nothing appears fake.


Computers, Inc. Recommendation

Businesses should:

  • Continue using Multi-Factor Authentication.
  • Train employees to recognize Device Code Phishing.
  • Monitor Microsoft 365 sign-in activity.
  • Consider Conditional Access policies that restrict Device Code authentication when it isn’t needed.

Bottom Line

Never enter a Microsoft device code unless you personally initiated the sign-in.

If someone sends you a device code and asks you to enter it, treat it as suspicious until you’ve confirmed the request with your IT department.

Related Resources

  • Multi-Factor Authentication
  • Password Security
  • How to Recognize and Avoid Phishing Attacks
  • Microsoft 365 Multi-Factor Authentication

Need Help?

If you have questions or need assistance, Computers, Inc. is here to help.

Submit a Ticket

Contact us:

Address:

Computers, Inc.

6280 South Valley View Blvd,Β 

Las Vegas, NVΒ  89118

Hours of operation:

9 am to 5 pm M-F

Phone Number:

702 450 6104

E-Ticket Submission

πŸ“± Scan to Access Computers, Inc. Mobile Tools (Submit tickets, make payments, leave reviews, or text us – all from your phone.)

Save link to your device desktop for quick and easy access

Your comments and suggestions are always welcome

Tech links