Unique Logo Interpretations for NOVAXIS TECHNOLOGY (5)
NOAVAXIS Technology

SECURITY ALERT · MICROSOFT 365

Microsoft 365 Device-Code Phishing: What Organizations Should Check After the EvilTokens Campaign

Microsoft's investigation into EvilTokens highlights how attackers can abuse legitimate device-code authentication to obtain tokens, access Microsoft 365 mailboxes and support business email compromise.

Published: September 28, 2026   ·   NOAVAXIS Technology Intelligence

EXECUTIVE SUMMARY

A legitimate authentication flow is being turned against users.

Microsoft Threat Intelligence has detailed activity involving EvilTokens, a phishing-as-a-service platform that supports device-code phishing, token theft and business email compromise.

Microsoft reports that campaigns facilitated by EvilTokens compromised more than 12,000 inboxes across over 10,000 organizations worldwide.

The technique is particularly important because victims can be directed to a legitimate Microsoft authentication experience. The attacker does not necessarily need to steal the user's password directly; instead, the victim can unknowingly authorize a session initiated by the attacker.

Security priority Organizations should understand whether device-code authentication is genuinely required in their environment and restrict it wherever possible.

HOW DEVICE-CODE PHISHING WORKS

The Microsoft sign-in page can be real. The request behind it is not.

Device-code authentication is a legitimate OAuth flow designed for devices that cannot easily provide a normal browser or keyboard-based sign-in experience.

In a legitimate scenario, a device displays a short code. The user opens a browser on another device, enters the code and completes authentication.

In a phishing scenario, the attacker starts the device-code flow and sends the resulting code to the victim through a deceptive message. If the victim enters that code and approves the authentication, the attacker-controlled session can receive access.

STEP 01

Attacker starts flow

A device-code authentication request is initiated.

STEP 02

Victim receives code

Social engineering convinces the user that the code is legitimate.

STEP 03

User authenticates

The victim enters the code into Microsoft's legitimate authentication flow.

STEP 04

Attacker gains session

The attacker can receive tokens associated with the authorized session.

EVILTOKENS CAMPAIGN

Phishing infrastructure built for scale.

According to Microsoft, EvilTokens developed into a widely used phishing-as-a-service platform after emerging in February 2026.

The platform provided prebuilt phishing templates, AI-assisted lure creation and infrastructure designed to support device-code phishing and token theft.

12,000+

inboxes Microsoft says were compromised through campaigns facilitated by the platform.

10,000+

organizations worldwide affected by those campaigns.

44

phishing themes observed by Microsoft, including invoices, RFPs and shared-file lures.

WHY THIS ATTACK MATTERS

The attack targets the authentication process rather than simply asking for a password.

Multifactor authentication remains an essential security control. However, Microsoft explains that device-code phishing can circumvent traditional MFA protections by separating the authentication event from the attacker-controlled session that initiated it.

This is why organizations need controls around authentication flows in addition to simply enabling MFA.

Important distinction MFA is still critical. The lesson from device-code phishing is that identity security also needs phishing-resistant authentication, Conditional Access, monitoring and control over higher-risk authentication flows.

AFTER COMPROMISE

Mailbox access can become the starting point for further abuse.

Microsoft observed stolen tokens being used for email access and exfiltration. Attackers also created malicious inbox rules to conceal communications and support persistence.

EvilTokens also provided capabilities to analyze compromised mailbox content and perform Microsoft Graph reconnaissance, helping attackers understand organizational relationships and identify additional opportunities for business email compromise or lateral movement.

WHAT ORGANIZATIONS SHOULD CHECK

Start with visibility before enforcing a tenant-wide block.

Device-code flow may still be legitimately required by Teams devices, developer tools, administrative tools or other scenarios. Organizations should identify those dependencies before enforcing changes.

1. Review device-code sign-ins

Use Microsoft Entra sign-in logs to identify where device-code authentication is currently being used and which users, applications and resources depend on it.

2. Identify legitimate dependencies

Determine whether Teams devices, Azure CLI, developer tools, administrative tools or legacy workflows genuinely require device-code authentication.

3. Block device-code flow where possible

Microsoft recommends blocking device-code flow wherever possible using Conditional Access.

4. Keep exceptions narrow

Where device-code authentication is required, scope exceptions to documented scenarios rather than broad user populations.

5. Review suspicious mailbox activity

Investigate suspicious inbox-rule creation, unexpected mailbox access, unusual sign-ins and other indicators associated with business email compromise.

6. Strengthen phishing resistance

Continue strengthening MFA with phishing-resistant authentication methods such as passkeys or FIDO-based credentials where appropriate.

CONDITIONAL ACCESS

Test before enforcing.

Microsoft Entra Conditional Access can explicitly target device-code authentication flow. Microsoft recommends organizations get as close as practical to blocking device-code flow while maintaining narrowly controlled exceptions for legitimate requirements.

Before moving a new policy into enforcement, review existing usage and use report-only mode to understand potential impact.

Don't create broad exceptions An exception intended for one legitimate device or workflow should not silently leave device-code authentication available to a large user population.

IF COMPROMISE IS SUSPECTED

Token theft requires an identity and mailbox response.

Microsoft recommends following compromised-account response guidance, revoking refresh tokens and investigating mailbox activity when suspected device-code phishing is identified.

Microsoft also notes that existing access tokens may remain active for a period after standard session revocation. In an active compromise, temporary account disabling may therefore be considered as part of immediate containment.

Incident response should also examine suspicious inbox rules, malicious forwarding, unusual authentication activity, affected devices and evidence of further account or organizational compromise.

NOAVAXIS RECOMMENDATION

Treat device-code flow as an exception, not a default.

Organizations should first establish whether device-code authentication has a legitimate business requirement.

Where it is not needed, block it. Where it is required, document the dependency, restrict the exception, assign an owner and review it regularly.

Practical review model Discover usage → Validate business need → Restrict authentication flow → Monitor exceptions → Investigate suspicious activity

MICROSOFT 365 IDENTITY SECURITY

Do you know where device-code authentication is being used?

NOAVAXIS can help review Microsoft Entra authentication activity, Conditional Access, device-code dependencies and identity security controls to identify unnecessary exposure and build a practical remediation plan.

Talk to NOAVAXIS