What Is the Device Code Flow?
The device code sign-in flow was created for devices that cannot display a full browser — think smart TVs, lobby kiosks, some printers, and meeting-room screens. Instead of a pop-up login window, the device shows a short code and tells the user to visit a real Microsoft page on any browser, enter the code, and sign in. Once they do, the device receives access to the account.
The legitimate flow looks like this:
Example — Lobby TV Setup (Legitimate)
To sign in, use a web browser to open:
microsoft.com/devicelogin
And enter the code:
FKBP-QJMN
✓ You turned on the TV yourself. ✓ You can see the screen. ✓ Nobody dictated the code to you.
An attacker contacts a staff member — by phone call, email, Teams message, or text — and gives them a code along with a convincing story. The staff member:
- Opens a browser and goes to microsoft.com/devicelogin (the real URL).
- Types in the code the attacker provided.
- Signs in with their church Microsoft 365 account.
- Completes MFA on their phone as normal.
- Microsoft says "You're all set!" — and the attacker's session is now authenticated.
From the staff member's point of view, nothing felt wrong. They visited a real Microsoft URL, signed in normally, and got a success message. The attacker now has a valid token for that account.
- You did not start a device sign-in yourself — no TV, printer, or device in front of you is showing a code.
- Someone is dictating a code to you verbally, by text, or by email — rather than you reading it off a screen.
- There is urgency: a deadline, a service that will stop working, a traveling pastor who needs it now.
- The request comes from an unknown number, a new contact, or someone you cannot verify through a second channel.
- You are asked to keep the action confidential or not mention it to the tech team.