I usually recommend an exclusion group managed by PIM or Access Packages :)
I usually recommend an exclusion group managed by PIM or Access Packages :)
You can assess impact via Entra sing-in logs (see picture) or Graph PowerShell:
Get-MgBetaAuditLogSignIn -Filter "AuthenticationProtocol eq 'deviceCode'"
CA template (Use Upload policy file in CA) here:
github.com/nathanmcn...
Volexity report: www.volexity.com/blo...
You can assess impact via Entra sing-in logs (see picture) or Graph PowerShell:
Get-MgBetaAuditLogSignIn -Filter "AuthenticationProtocol eq 'deviceCode'"
CA template (Use Upload policy file in CA) here:
github.com/nathanmcn...
Volexity report: www.volexity.com/blo...
```powershell
Connect-ExchangeOnline -DeviceCode
Connect-MgGraph -UseDeviceAuthentication
```
Annoying to have to use another device that has a GUI, but it's an option.
```powershell
Connect-ExchangeOnline -DeviceCode
Connect-MgGraph -UseDeviceAuthentication
```
Annoying to have to use another device that has a GUI, but it's an option.
badoption.eu/blog/2024/01...
badoption.eu/blog/2024/01...
agderinthe.cloud/2025/01/31/i...
agderinthe.cloud/2025/01/31/i...
www.bleepingcomputer.com/news/securit...
www.bleepingcomputer.com/news/securit...
#Microsoft #Phishing #DeviceCode
#Microsoft #Phishing #DeviceCode
#Cybercriminals, including state-sponsored threat actors, are increasingly abusing #Microsoft’ s #OAuth2.0 #devicecode #authentication flow to take over #Microsoft365 accounts.
www.techradar.com/pro/security...
#Cybercriminals, including state-sponsored threat actors, are increasingly abusing #Microsoft’ s #OAuth2.0 #devicecode #authentication flow to take over #Microsoft365 accounts.
www.techradar.com/pro/security...