This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
Microsoft 365 and Azure Device Code (Device Code) Abuse
Device Code authentication is a legitimate feature that addresses a practical problem — it allows convenient sign-in on devices without a browser or full keyboard, using username, password, and multi-factor authentication. The Device Code Flow authentication process can be illustrated with an example: in a meeting room, there is a display system designed for online conferences, such as Microsoft Teams Rooms or an equivalent solution. The Device Code Flow technology is not about exploiting software vulnerabilities or hacking, but about phishing, where an attacker maliciously exploits a standard product feature and deceives the user. The device code, as well as any login data, should only be entered if all the following conditions are met: Never enter codes received via email, Teams messages, communication platforms, or phone calls! 1) First, enable Microsoft Entra security defaults. Instructions for fully blocking the Device Code with MS Entra system settings 'Security Defaults': more details at https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults 2) Another way to prevent Device Code usage is by creating a Conditional Access policy.