What is Device Code Authentication?
Despite conventional phishing techniques remaining effective, cyber criminals continue looking for new ways to compromise users' accounts. One lesser-understood method to do so is through device codes. Traditional authentication involves a username and a password; this can be extremely inconvenient or even impossible for devices lacking a keyboard or other way for users to input their credentials. Smart TVs and Internet-of-Things (IoT) devices are examples of "input-constrained" devices which may need to log into applications.
Device code authentication offloads authentication to a different device, such as a user's smartphone or computer. The "input-constrained" device's application generates a code for users to input on their alternative device and advise users to visit a legitimate link on the application developer's website (Microsoft, Netflix, etc.). Users will then go through their usual authentication process on a legitimate login page- username, password, 2-factor authentication. Afterwards, a token will be provided to the "input-constrained" device's app giving it access to the user's account.
However, a device using device code authentication does not actually need to be "input-constrained".
How does Device Code Phishing Work?
Consider the typical case of an attacker attempting to compromise a user's Microsoft 365 account:
- An attacker visits a Microsoft application and initiates a device code authentication. They receive a device code. The attacker does not require a username or password to do this; the authentication is not against anyone in particular at this stage.
- The attacker contacts their target via message, email, or phone call. Alternatively, codes can be generated when a user visits a malicious or compromised website under the guise of "verification". Their objective is to convince the user to visit the official Microsoft device code login page and enter the attacker's code.
- The target enters the device code and then goes through their regular Microsoft authentication flow on the official Microsoft website, including 2-factor authentication if enabled.
- Microsoft issues a token to the attacker's device granting access to the target's account.

Why is Device Code Phishing Effective?
There are several reasons why this technique is effective:
- Users are unlikely to understand what device code authentication is, or how it works.
- The attack occurs exclusively on legitimate domains/websites. A user suspicious of fake or look-a-like websites would only encounter trusted, official websites during the attack.
- Generative AI is capable of crafting convincing, personalized phishing messages to send users. AI can also address users' replies in an attempt to alleviate suspicion and provide additional, fake context around the device code request.
- Traditional login-related alerts may not work against device code phishing attacks due to authentication taking place on users' regular, trusted devices rather than the attacker's devices.
How can You Protect Yourself Against Device Code Phishing?
Many of the usual behaviours and defenses that protect against phishing and scams apply:
- Treat unsolicited messages asking you to enter a code with extreme suspicion. If you did not request a code, you should not be receiving one.
- Verify the identity of senders (email addresses, phone numbers). Consider the possibility that a trusted contact could have been compromised to send you phishing messages, or that a phone number was "spoofed" to appear as a trusted number.
- Carefully review warnings prior to clicking on links or entering codes; the Microsoft device code input page states that entering a code will grant account access to whoever generated it.
- Report suspicious messages to York University IT, York University's Information Security team, or trusted colleagues for a second opinion.
Questions?
York University's Information Security team can be reached at infosec@yorku.ca. Phishing emails can be reported to phishing@yorku.ca. General inquiries around IT can be directed to askit@yorku.ca.
References
- https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/?msockid=047ea62ec25164ad1aeeb0d0c38065a2
- https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/device-code-flow-the-gift-that-keeps-on-giving-%E2%80%94-to-attackers/4540949
