Microsoft 365 device-code phishing defenses for OAuth token abuse
Defensive Guidance
Summary
Hide ▲
Show ▼
Defenders are tightening Microsoft 365 protections against device code phishing and vishing, a technique that can hand attackers valid OAuth tokens for Microsoft Entra accounts. The guidance focuses on blocking malicious infrastructure, revoking suspicious app consents, and watching for device code authentication events before token reuse can spread across connected services.
Related Happenings
ShinyHunters-linked Salesforce intrusion campaign
Campaign
H score45
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
ShinyHunters-linked Salesforce intrusion campaign
CampaignAbout this happening: A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
Microsoft Entra OAuth Client ID spoofing campaign
Campaign
H score58
First: 13.07.2026 16:00
Last: 13.07.2026 16:00
Sources 1
About this happening:
A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
Microsoft Entra OAuth Client ID spoofing campaign
CampaignAbout this happening: A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
Microsoft Azure CLI password-spray campaign using ROPC
Campaign
H score24
First: 01.07.2026 08:46
Last: 01.07.2026 08:46
Sources 1
About this happening:
A massive automated password-spray campaign against Microsoft Azure CLI compromised at least 78 accounts across 64 organizations, expanding access risk across clou...
Microsoft Azure CLI password-spray campaign using ROPC
CampaignAbout this happening: A massive automated password-spray campaign against Microsoft Azure CLI compromised at least 78 accounts across 64 organizations, expanding access risk across clou...
EvilTokens Microsoft 365 consent phishing campaign
Campaign
H score39
First: 19.05.2026 14:30
Last: 19.05.2026 14:30
Sources 1
About this happening:
The EvilTokens campaign rapidly compromised more than 340 Microsoft 365 organizations across five countries, showing how OAuth grant abuse can bypass MFA and c...
EvilTokens Microsoft 365 consent phishing campaign
CampaignAbout this happening: The EvilTokens campaign rapidly compromised more than 340 Microsoft 365 organizations across five countries, showing how OAuth grant abuse can bypass MFA and c...
Microsoft AiTM payroll pirate attack mitigation
Advisory/Mitigation
H score34
First: 10.04.2026 14:56
Last: 10.04.2026 14:56
Sources 1
About this happening:
Microsoft is urging defenders to harden Microsoft 365 and related HR workflows against AiTM-driven payroll theft by requiring phishing-resistant MFA, blocking...
Microsoft AiTM payroll pirate attack mitigation
Advisory/MitigationAbout this happening: Microsoft is urging defenders to harden Microsoft 365 and related HR workflows against AiTM-driven payroll theft by requiring phishing-resistant MFA, blocking...
Timeline
-
19.02.2026 14:30 2 articles · 4mo ago
Microsoft 365 defenses against device code phishing
Mitigation Patch UpdateKnowBe4 Threat Labs guidance focuses on hardening Microsoft 365 against device code phishing and vishing that abuse the OAuth 2.0 Device Authorization flow to obtain valid authentication tokens for Microsoft Entra accounts. Recommended controls include blocking malicious domains and sender addresses, auditing and revoking suspicious OAuth app consents, reviewing Azure AD sign-in logs for device code authentication events, turning off the device code flow option when it is not required, and enforcing conditional access policies; the same reporting context notes a campaign first spotted in December 2025 and a Microsoft Threat Intelligence Center warning from February 2025 about device code phishing.
Show sources
- Hackers target Microsoft Entra accounts in device code vishing attacks — www.bleepingcomputer.com — 19.02.2026 14:30
- Hackers target Microsoft Entra accounts in device code vishing attacks — www.bleepingcomputer.com — 19.02.2026 14:30