← All guides

Identity security

What is device-code phishing?

Understand the legitimate device authorization flow, how social engineering can misuse it, and what to examine in sign-in logs.

The short answer

Device-code sign-in is legitimate for devices with limited input. In a phishing attempt, an attacker initiates the flow and persuades a user to enter the code, authorizing the attacker's session or app instead of their own device.

The telltale context

Check the authentication flow, application and resource, who initiated the request, the device used to complete it, and follow-on account activity. A device-code event by itself is not malicious: some organization-approved devices depend on this flow.

Contain proportionately

If misuse is supported by evidence, revoke the affected session or grants, assess accessed resources, and follow your identity-response playbook. Consider restricting device-code flow where it is unnecessary while documenting legitimate exceptions.

Make the call yourself

The investigation is a fictional, simulated learning scenario. Work through the evidence before reading the outcome.

Investigate suspicious app access →

Further reading

External references support the concepts; examples on CyberTap are original learning simulations.