Detecting Device Code Phishing: Defender XDR and Sentinel Hunting Queries
Device code phishing produces sign-ins with a distinctive authentication protocol. These detections help catch it even where the flow isn't yet blocked.
Signals worth watching
- Sign-ins using the device code authentication protocol by users who don't normally use it.
- Device code sign-ins where the user's location differs from the IP that redeemed the tokens.
- Device code sign-ins followed by mailbox access, inbox rule creation or data downloads from unfamiliar IPs.
- Many users completing device code sign-ins within a short window (campaign activity).
- Entra ID Protection risk detections associated with the sessions.
Where the data lives
- Entra ID sign-in logs (
AuthenticationProtocolfield) and non-interactive sign-in logs. - Unified audit log for mailbox activity.
- Defender XDR alerts.
A starting query
Device code sign-ins in the last day:
SigninLogs
| where TimeGenerated > ago(1d)
| where AuthenticationProtocol == "deviceCode"
| project TimeGenerated, UserPrincipalName, AppDisplayName, IPAddress, Location, ResultType, DeviceDetail
Users outside an approved list:
let approved = dynamic(["teamsroom1@contoso.com", "teamsroom2@contoso.com"]);
SigninLogs
| where AuthenticationProtocol == "deviceCode" and ResultType == "0"
| where UserPrincipalName !in~ (approved)
| summarize Count = count(), IPs = make_set(IPAddress) by UserPrincipalName
Response
- Revoke sessions and refresh tokens for affected users.
- Review mailbox and file activity after the sign-in.
- Remove malicious inbox rules and OAuth consents.
- Block device code flow with Conditional Access.
Sources
- EvilTokens (Mar 2026): Device Code Phishing-as-a-Service Hits Microsoft 365 Incident Teardowns
- How to Block Device Code Flow With Conditional Access How-To & Hardening
- CIO Brief: The Phishing Attack Where Users Complete MFA for the Attacker CIO Briefings