INFORMAZIONI SU QUESTO EPISODIO
Device code flow attacks are exploding across Microsoft 365 environments in 2025, and they bypass many of the security controls organizations rely on, including FIDO2 keys, MFA, and Conditional Access. In this episode of Demystifying Microsoft, host Nathan Taylor breaks down exactly how these attacks work, why threat actor groups like Storm-2372 are leveraging phishing-as-a-service kits like Kali365, Octopi365, FlowerStorm, and EvilTokens to industrialize the attack, as well as how to detect and block device code phishing in your own tenant.
What You’ll Learn:
- What device code flow sign-in is
- How to detect device code flow activity in your tenant
- Why device code flow attacks bypass your strongest security controls
- How to build the conditional access policy that blocks it
- Who's behind the current wave of attacks?
- How to handle legitimate exceptions safely
About the Host:
Nathan Taylor is the Senior Vice President and Global Microsoft Practice Leader at the Sourcepass Center of Excellence for Microsoft. With more than 20 years of experience supporting small and mid-sized organizations, Nathan brings a pragmatic perspective shaped by real-world deployments, Microsoft 365 security strategy, and close collaboration with Microsoft. He helps IT leaders cut through the noise of an ever-evolving Microsoft ecosystem so they can make informed, defensible decisions with confidence.
- 01:54 What Is Device Code Flow Sign-In?
A legitimate Microsoft authentication method built for conference room PCs, digital signage, and devices without a proper keyboard or browser.
- 04:16 Why Device Code Flow Bypasses MFA, FIDO2, and Conditional Access
The victim completes a fully legitimate Microsoft login on their trusted device, passing MFA and FIDO2 checks, then hands the resulting token to the attacker.
- 05:43 Storm-2372, Midnight Blizzard, and the Rise of Phishing-as-a-Service
The Storm-2372 threat actor group is driving this attack through WhatsApp, Signal, and Microsoft Teams messages. Phishing-as-a-service kits like Kali365, Octopi365, Freedom365, and EvilTokens have industrialized the attack and made it accessible to low-skill actors.
- 08:40 Hands-On Demo: Detecting Device Code Flow in Microsoft Entra
Go to entra.microsoft.com → Users → Sign-in logs, set the range to one month, and filter by authentication protocol. Always run this audit before deploying a block policy to avoid breaking legitimate logins.
- 10:58 Building the Conditional Access Policy to Block Device Code Flow
Create a new CA policy targeting all users and all resources, add the authentication flows condition for the device code flow, and set the grant control to block access. A five-minute change that hardens every tenant.
- 12:56 Handling Legitimate Use Cases
For conference room PCs, kiosks, or scripts that genuinely need device code flow, exclude the specific account and layer compensating controls: lock it to a single office IP, require phishing-resistant MFA, or require an Entra hybrid joined compliant device.
- 17:31 Why You Still Need an ITDR Tool Like Petra
Blocking device code flow doesn’t cover every attack path. An Identity Threat Detection and Response tool monitors sign-in behavior 24/7, catches unusual token activity, and can lock accounts before attackers exfiltrate data via Graph API.
Still figuring out whether your tenant is exposed to device code flow attacks or which conditional access policies you actually need? Connect with the Sourcepass MCOE team to build a Microsoft 365 security posture that blocks tomorrow’s attack vectors before they hit: https://sourcepassmcoe.com/demystifying-microsoft-contact
Nathan Taylor on LinkedIn
- “Before we put in a policy to block it, you really want to understand the impact on your org because you may have legitimate uses of this.”
- “The downside of device code flow is if a threat actor sends you this link and the code and you pull it up, you're probably filling it out on your trusted device.”
- “Tools like an ITDR certainly help me rest better at night, knowing that 24/7, there's a team watching for suspicious things.”
- “It's a clean, legitimate Microsoft login that you're filling in your MFA for, you're passing your FIDO2 keys, and it's authenticating you. And then it passes back to the threat actor a token.”
Demystifying Microsoft is handcrafted by our friends over at: fame.so
Inglese
Stati Uniti
TRASCRIZIONE 🔗
Are you the producer of this podcast?
Add a podcast transcript
Need Audio-to-Text?
Transcribe with Listen411 in Just 60 Seconds
CERCA TRA GLI EPISODI PASSATI
Cerca gli episodi passati di Demystifying Microsoft.
ALTRI EPISODI IN QUESTO PODCAST
The speed of AI innovation means that proofs of concepts that once took years now reach production in weeks. Nathan Taylor and Chance Weaver analyze how workflows went from chat interfaces to sophisticated agentic workflows within the Microsoft ecosystem. They even discuss Sourcepass MCOE’s experie…
AI agents and Copilot for Microsoft 365 are transforming how teams manage data, but the sheer volume of options often leads to organizational paralysis. Nathan Taylor and Brittney Saultman address how the agent store can be overwhelming. By beginning with specific business outcomes, the way forward…
GoDaddy can make Microsoft 365 easy to adopt when a company is small. The friction tends to appear later, when IT needs access to controls that sit outside GoDaddy’s managed experience.
In this episode of Demystifying Microsoft, Nathan Taylor sits down with Lindsay Cowan, Senior Sales and Business …
Moving into an AI-centered workflow is a continuous process of trying, learning, and iterating rather than a one-time software rollout. Steve Adams highlights that while technology changes by the hour, human instincts and organizational habits often lag years behind. To see a real return on investm…
Microsoft has a habit of dropping new capabilities into subscriptions without much noise. Business Premium is no longer just a "basic" option for small teams and Austin Kelly highlights why. The most immediate gain is the increase to a 100GB mailbox, which removes a long-standing frustration for he…
Dichiarazione di non responsabilità: Il podcast e la grafica incorporati in questa pagina provengono da Sourcepass Center of Excellence for Microsoft, che è di proprietà del suo proprietario e non è affiliato o approvato da Listen Notes, Inc.
MODIFICA
Grazie, ci hai aiutato a mantenere aggiornato il database dei podcast.