Device Code Phishing: 5 Steps to Protect Your Business

by The Creator | Sep 22, 2026

Business owner reviewing device code phishing protection steps on computer to secure Microsoft 365 accounts

Device code phishing represents a new twist on an old problem: getting into your business accounts without needing a password. Microsoft recently shut down a service called EvilTokens that made these attacks easy to execute at scale, but the technique remains a live threat to any business using Microsoft 365, especially those without dedicated IT security staff.

What is device code phishing and how does it work?

Device code phishing exploits a legitimate authentication method built into Microsoft 365 and similar cloud platforms. Here’s the pattern: An attacker sends your employee an email or message (often disguised as a security alert or IT notice) containing a link. When clicked, the link takes them to a real Microsoft login page that displays an authentication code. The employee is instructed to enter that code on another page, which looks official but is controlled by the attacker.

Once the code is submitted, the attacker gains full access to the account. No password was stolen. No malware was installed. The employee followed what appeared to be standard authentication steps, and the attacker walked through an open door.

This method works because it relies on a feature designed for convenience: the device code flow lets users authenticate on devices that can’t easily handle standard login processes (think smart TVs or IoT devices). Attackers simply repurpose this flow to trick employees into handing over access tokens, the digital keys that prove identity to Microsoft’s systems.

Why are small businesses targeted by device code phishing?

Your business may not have the data volume of a Fortune 500 company, but you have something just as valuable: likely weaker defenses and staff who wear multiple hats. Attackers know that a 30-person professional services firm probably hasn’t trained employees on this specific attack pattern. They also know that smaller organizations often lack the conditional access policies and device management controls that flag suspicious authentication attempts.

The EvilTokens service that Microsoft disrupted charged criminals a subscription fee to automate these attacks. That business model only works if there’s a steady supply of vulnerable targets. Manufacturing companies, law firms, accounting practices, and insurance agencies in Connecticut and beyond fit that profile perfectly: they use Microsoft 365 for email and file sharing, they have valuable client data, and they often rely on generic security awareness training that doesn’t cover device code flows.

When an attacker gains access to a single account, the damage compounds quickly. Email threads reveal client names, project details, and financial information. Shared OneDrive folders expose contracts and proprietary documents. Calendar entries show who’s traveling and when offices are lightly staffed. For a business built on client trust, a data breach stemming from one compromised account can mean notification letters, regulatory scrutiny, and clients quietly moving to competitors.

What happened with the EvilTokens disruption?

Microsoft’s Threat Intelligence team identified and dismantled EvilTokens, a phishing-as-a-service platform that automated device code phishing campaigns. The service provided attackers with ready-made phishing pages, email templates, and a management dashboard to track compromised accounts. It lowered the technical barrier to entry, meaning criminals without deep coding skills could launch sophisticated attacks.

The disruption involved taking down the infrastructure hosting the service and working with domain registrars to block associated sites. But here’s the reality: shutting down one service doesn’t eliminate the technique. Other platforms will emerge, and the device code authentication flow remains a standard feature in Microsoft 365. The method itself is not going away.

For professional services firms and manufacturers, this means you can’t rely on Microsoft or law enforcement to solve the problem for you. Your defense has to be proactive, combining technical controls with a staff that recognizes the warning signs.

What are five practical steps to prevent device code phishing?

Protection starts with understanding that this attack uses trust in familiar brands and standard login processes. Your team needs to know what normal authentication looks like and when to pause and verify.

1. Train employees to recognize device code requests. Most employees have never heard of device code authentication. Run a 10-minute briefing explaining that if they receive an unexpected email asking them to enter a code on a separate page, they should stop and contact IT or your managed service provider before proceeding. Use a real example: show them what a phishing email looks like next to a legitimate authentication request. Repetition matters. Make this part of your quarterly security refreshers, not a one-time lecture.

2. Enable conditional access policies in Microsoft 365. These policies let you define rules for how and where users can authenticate. For example, you can require that logins come from known devices or trusted IP address ranges. If an attacker in another country tries to authenticate using a stolen token, the system blocks or challenges the attempt. This adds a second layer beyond the initial login, catching attacks even if an employee falls for a phishing email. Most small businesses don’t configure these policies because they assume they’re too complex or expensive. They’re neither.

3. Require multi-factor authentication (MFA) with device trust verification. Basic MFA (a code sent to a phone) helps, but it won’t stop device code phishing because the attacker is tricking the employee into completing the MFA step for them. Instead, configure MFA to require device trust: the authentication must come from a device registered in your Azure Active Directory environment. This prevents attackers from using tokens on their own machines.

4. Monitor sign-in logs for unusual authentication patterns. Microsoft 365 provides sign-in logs that show where and how accounts are accessed. Look for device code flows that occur outside your normal business processes. If you see unexpected device code authentications, especially from unfamiliar locations or at odd hours, investigate immediately. This is where a managed service provider with security operations experience becomes valuable: they watch these logs daily and flag anomalies before they become breaches.

5. Disable device code flow if your business doesn’t use it. For many small businesses, the device code authentication method serves no legitimate purpose. If your team logs in from laptops and phones using standard methods, you can disable device code flows entirely through Azure AD authentication policies. This eliminates the attack vector. Talk to your IT provider about whether this makes sense for your environment. If you’re not using it, turn it off.

What should you do if you suspect a device code phishing attack?

Speed matters. If an employee reports clicking a suspicious link or entering an authentication code they didn’t request, assume the account is compromised and act immediately.

First, reset the user’s password and revoke all active sessions in Microsoft 365. This logs the attacker out and forces a new authentication. Second, review the account’s recent activity: check sent emails, file access logs, and calendar changes. Attackers often move quickly to exfiltrate data or set up forwarding rules before you notice. Third, scan for persistence mechanisms. Attackers may create inbox rules to hide their activity, add external forwarding addresses, or register new devices to maintain access even after a password reset.

Document everything. If the breach exposed client data, you may need to notify affected parties and, depending on your industry, report to regulators. Connecticut law firms handling HIPAA-covered information, for instance, face specific notification timelines and requirements. Manufacturers working with Department of Defense contracts need to consider CMMC (Cybersecurity Maturity Model Certification) implications. An ounce of documentation during the incident saves a pound of reconstruction later when regulators or insurance carriers ask questions.

Finally, conduct a brief post-incident review. What allowed the attack to succeed? Was it a training gap, a missing technical control, or both? Make one or two specific changes to close that gap. Downtime and disruption are expensive teachers, but only if you learn the lesson.

Do small businesses really need to worry about device code phishing?

Yes, because the attacks are cheap to execute and SMBs statistically respond less quickly than enterprises. Attackers aren’t after your business specifically in most cases. They’re casting wide nets and exploiting whoever bites. The EvilTokens service automated thousands of attempts, and the criminals behind it didn’t care whether they compromised a law firm in Hartford or a machine shop in Litchfield County. They cared about access, and once inside, they sold that access or used it for further attacks.

The cost question is worth addressing plainly. Implementing conditional access policies and device trust doesn’t require new software licenses if you’re already using Microsoft 365 Business Premium or Enterprise plans. It requires configuration time, typically a few hours of work by someone who knows Azure AD. Training employees takes a lunch-and-learn session. Monitoring sign-in logs can be handled by your existing IT provider if you ask them to add it to their scope. The expense is measured in hundreds of dollars or low thousands at most, depending on your provider and environment complexity.

Compare that to the cost of a breach: notification letters, forensic investigation, legal fees, potential regulatory fines, and the impossible-to-quantify loss of client trust. A single compromised account at a 20-person accounting firm led to exposed tax returns for 300 clients last year. The firm survived, but two partners spent six months doing nothing but damage control. That’s the real cost. Prevention is cheaper.

What comes next for phishing attacks?

Attackers adapt. Device code phishing works today because it’s relatively new to most employees and IT teams. As awareness grows and defenses improve, criminals will shift to other methods. We’ve already seen AI-generated phishing emails that mimic writing styles and reference real projects. We’ve seen attackers compromise legitimate business partner accounts and send malicious links from trusted email addresses.

The pattern holds: attackers look for the path of least resistance. For small businesses, that path often runs through under-trained employees and under-configured cloud services. Your goal isn’t to build a fortress (you can’t, and you don’t need to). Your goal is to be a harder target than the business next door. Make the attacker work for access, and they’ll often move on.

This means staying current. Subscribe to security alerts from your IT provider or trusted sources. When Microsoft publishes guidance on a new attack method, read it. When your provider recommends a policy change, ask questions but don’t dismiss it. Cybersecurity is not a project with a finish line. It’s an ongoing conversation between your business needs, your risk tolerance, and the threat environment.

Device code phishing is one threat in a long list. It’s not the scariest or the most sophisticated. But it’s real, it’s active, and it’s targeting businesses exactly like yours. The good news: the defenses are within reach and the awareness gap is closable. You just have to close it before an attacker finds it first.

Keep reading

Sources

Source: Microsoft Disrupts EvilTokens Device Code Phishing Service