Device Code Phishing

What Is the Device Code Flow?

The device code sign-in flow was created for devices that cannot display a full browser — think smart TVs, lobby kiosks, some printers, and meeting-room screens. Instead of a pop-up login window, the device shows a short code and tells the user to visit a real Microsoft page on any browser, enter the code, and sign in. Once they do, the device receives access to the account.

The legitimate flow looks like this:

Example — Lobby TV Setup (Legitimate)

To sign in, use a web browser to open:

microsoft.com/devicelogin

And enter the code:

FKBP-QJMN

✓ You turned on the TV yourself. ✓ You can see the screen. ✓ Nobody dictated the code to you.

What Your Staff Sees (Victim-Facing View)

An attacker contacts a staff member — by phone call, email, Teams message, or text — and gives them a code along with a convincing story. The staff member:

  1. Opens a browser and goes to microsoft.com/devicelogin (the real URL).
  2. Types in the code the attacker provided.
  3. Signs in with their church Microsoft 365 account.
  4. Completes MFA on their phone as normal.
  5. Microsoft says "You're all set!" — and the attacker's session is now authenticated.

From the staff member's point of view, nothing felt wrong. They visited a real Microsoft URL, signed in normally, and got a success message. The attacker now has a valid token for that account.

Church Scenarios to Watch For

Red Flags to Recognize
  • You did not start a device sign-in yourself — no TV, printer, or device in front of you is showing a code.
  • Someone is dictating a code to you verbally, by text, or by email — rather than you reading it off a screen.
  • There is urgency: a deadline, a service that will stop working, a traveling pastor who needs it now.
  • The request comes from an unknown number, a new contact, or someone you cannot verify through a second channel.
  • You are asked to keep the action confidential or not mention it to the tech team.