Device code phishing uses the real microsoft.com/devicelogin page. MFA succeeds, the attacker gets the tokens. Block Authentication flows > Device code in Conditional Access, report-only first.
Device code phishing uses the real microsoft.com/devicelogin page. MFA succeeds, the attacker gets the tokens. Block Authentication flows > Device code in Conditional Access, report-only first.