π¨ Security Alert
Why This Matters
Most businesses have improved their security by enabling Multi-Factor Authentication (MFA).
Unfortunately, attackers have adapted.
Instead of trying to steal passwords, they now try to convince users to approve a legitimate Microsoft sign-in request that grants access to the attacker’s device.
Because the sign-in occurs through Microsoft’s own systems, everything can appear completely legitimate.
How the Scam Works
An employee receives an email or Teams message claiming they need to:
- Join a meeting
- Open a shared document
- Verify their Microsoft account
- Activate a collaboration tool
The message directs them to Microsoft’s legitimate Device Login page.
They enter a short code provided by the attacker.
The employee signs in with Microsoft 365.
They approve the MFA request.
The attacker is now signed in.
No password was stolen.
No malware was installed.
The attacker simply convinced the employee to approve their own access.
Warning Signs
Be suspicious if you are asked to:
- Visit microsoft.com/devicelogin
- Enter a device code that someone else provided
- Approve an unexpected Microsoft sign-in
- Authenticate for a meeting or collaboration request you didn’t initiate
If you weren’t expecting it, stop.
What You Should Do
If you receive an unexpected device code request:
- Do not enter the code.
- Do not approve the MFA request.
- Report the message to your IT department.
- Change your Microsoft 365 password if you believe you completed the request.
Why This Attack Is Different
Traditional phishing tries to steal your password.
Device Code Phishing uses Microsoft’s own authentication process.
That makes the attack much harder to recognize because nothing appears fake.
Computers, Inc. Recommendation
Businesses should:
- Continue using Multi-Factor Authentication.
- Train employees to recognize Device Code Phishing.
- Monitor Microsoft 365 sign-in activity.
- Consider Conditional Access policies that restrict Device Code authentication when it isn’t needed.
Bottom Line
Never enter a Microsoft device code unless you personally initiated the sign-in.
If someone sends you a device code and asks you to enter it, treat it as suspicious until you’ve confirmed the request with your IT department.
Related Resources
- Multi-Factor Authentication
- Password Security
- How to Recognize and Avoid Phishing Attacks
- Microsoft 365 Multi-Factor Authentication