●  Melbourne-based · Local support you can actually reach
← All insights
Cyber security

The Microsoft login page was real. That's exactly the problem

A staff member gets chatting to someone over the week, a contact who seems legitimate and relevant to their work. A meeting gets arranged. An invitation arrives, and to join, they’re asked to sign in to Microsoft. They land on the genuine Microsoft login page, the real one, at the real address, and they’re asked to enter a short code. They do. Everything looked exactly right.

And with that, they’ve handed their entire Microsoft 365 account to an attacker. Their password was never stolen. Their multi-factor authentication worked perfectly. Both of the things you’ve been told will protect you did nothing, because this attack is built to turn them against you. It’s called device code phishing, and it’s worth understanding, because it defeats the advice most people are relying on.

Why this one is different

Most phishing tries to trick you into typing your password into a fake website. The standard defences are built around that: check the web address, look for the dodgy link, and turn on multi-factor authentication so a stolen password isn’t enough.

Device code phishing does none of that. There’s no fake website, no copycat domain, and no form harvesting your password. The attacker sends you to the real Microsoft sign-in page, because they want you to use it. All they need is for you to type in a short code they give you. When you do, you’re not logging yourself in. You’re approving their login, on their device, into your account.

How it unfolds

The legitimate version of this exists for a reason. The “device code” sign-in was designed for gadgets that are awkward to type on, like a smart TV or a meeting-room screen, where you enter a code on your phone to sign the device in. Attackers have learned to abuse it.

Microsoft reported a campaign in early 2025 by a group it tracks as Storm-2372, assessed as aligned with Russian interests, that ran exactly this play against governments, organisations and businesses. The pattern looks like this:

  1. The attacker starts a real device sign-in request with Microsoft and gets a genuine code, valid for a few minutes.
  2. They contact the target, often after building a bit of rapport first over a messaging app or Teams, and send a meeting invite or a prompt to sign in.
  3. The target goes to the real Microsoft page and enters the code, believing they’re joining a meeting or confirming their account.
  4. That action approves the attacker’s session. Microsoft hands the attacker valid access tokens, and they’re inside the account.

Because the victim completes their own multi-factor authentication as part of it, the attacker inherits a session that has already passed every check. Worse, the access they’re granted can survive a password reset, which makes cleaning up afterwards genuinely hard.

Why your usual defences miss it

Line up the three things people lean on, and watch all three fail here:

  • “Check the link.” The link is real. It’s Microsoft’s actual sign-in page. There’s nothing suspicious to spot.
  • “Use a strong password.” Your password is never entered or stolen. It’s irrelevant to the attack.
  • “Turn on MFA.” You complete the MFA yourself, for the attacker. It doesn’t stand in their way, it clears the path.

That’s what makes this one important. It’s not that those defences are bad. It’s that this specific attack is designed to slip past all of them, which is why it needs its own answer.

The switches that stop it

The good news is that the fix is clean, and for most businesses it costs nothing and changes nothing about daily work:

  • Switch off device code sign-in if you don’t use it. The vast majority of small businesses never need it. Microsoft lets you block it with a Conditional Access policy, which closes the door this attack walks through entirely. If a few specific people genuinely need it, you can allow just them.
  • Teach one simple rule. Only ever enter a device code into a Microsoft page when you are setting up a device yourself, right now, with it in your hands. If a code arrives from someone else, in a message, an email or a meeting invite, never type it in. That single habit defeats the whole thing.
  • Be wary of the warm-up. A new contact who’s friendly over a few days and then asks you to “sign in to join” is the classic setup. Slow down when a sign-in request arrives out of a conversation.
  • If it happens, revoke, don’t just reset. Because the stolen access can outlive a password change, the response is to revoke active sessions and sign-in tokens, not only reset the password. This is where having someone who knows Microsoft 365 properly earns its keep.

The takeaway

Device code phishing is a reminder that “the page is real and my MFA worked” isn’t always the all-clear it feels like. The defence isn’t more suspicion of links, it’s one configuration change and one clear rule for your team. Turn off the door you don’t use, tell your people never to enter a code someone sent them, and an attack that beats passwords and MFA suddenly has nothing to work with.

Want this attack shut off in your Microsoft 365?

Book a free, no-obligation security assessment. We'll check whether your Microsoft 365 is exposed to device code phishing, and switch off the door it walks through.

Actively managed IT

Want your protection this clear?

Every article here comes from how we look after Melbourne businesses every day. See where your business stands, and what “actively managed” really feels like.

Book a free assessment

Or explore cyber security in Melbourne.