A Real Sign-In Page, the Wrong Person
Someone asks you to enter a code on a genuine sign-in page. Doing so can sign them into your account.
Illustrative scenario
How It Looks in Real Life
A contact invites you to a meeting and says: “Go to the official Microsoft device login page and enter code ABCD-1234 to join.” The page is real.
Understand it
How the Attack Works
Device-code sign-in lets devices without keyboards, such as TVs, sign in using a code entered elsewhere. Attackers start that flow themselves and send you the code. When you enter it, their device receives access to your account.
Red flags
Warning Signs
- Anyone other than a device in front of you supplying a sign-in code.
- Codes sent through chat, email or messaging apps to “join a meeting” or “verify”.
- A prompt saying you are signing in on a device you do not have.
Safer habits
What to Do Instead
- 1Only enter device codes shown on a device you are personally setting up.
- 2Remember that a genuine authentication domain does not prove the requester is trustworthy.
- 3Report unexpected code requests to IT.
Response playbook
Already Interacted?
For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.
If you: approved app permissions or a sign-in request
- 1Report it straight away so IT can revoke the session or app consent.
- 2Remove the unfamiliar app from your account’s connected apps or permissions page.
- 3Changing your password does not remove app permissions or tokens already issued.
If you: entered credentials or shared a code
- 1Report it to IT or security immediately for a work account; speed matters more than embarrassment.
- 2Change the password from a trusted device by typing the real address yourself.
- 3Sign out of all sessions from the account security settings. A password change alone may not end active sessions.
- 4Review recovery email, phone number and forwarding rules for unexpected changes.
Knowledge Check
What Would You Do?
A new “partner” sends a code and asks you to enter it on the official sign-in page to access a shared file. Safe choice?
Fictional example for learning. Not a test score or certification.
Sources
- Microsoft Security Blog: Defending against evolving identity attack techniques (May 2025)
- Microsoft Learn: Block authentication flows (device code)
Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.
Make Safe Habits Part of Your Culture
Plain-language awareness sessions for everyday staff, developers and business teams.