Microsoft 365Detection & ResponseNews

Detecting Device Code Phishing: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Device code phishing produces sign-ins with a distinctive authentication protocol. These detections help catch it even where the flow isn't yet blocked.

Signals worth watching

  • Sign-ins using the device code authentication protocol by users who don't normally use it.
  • Device code sign-ins where the user's location differs from the IP that redeemed the tokens.
  • Device code sign-ins followed by mailbox access, inbox rule creation or data downloads from unfamiliar IPs.
  • Many users completing device code sign-ins within a short window (campaign activity).
  • Entra ID Protection risk detections associated with the sessions.

Where the data lives

  • Entra ID sign-in logs (AuthenticationProtocol field) and non-interactive sign-in logs.
  • Unified audit log for mailbox activity.
  • Defender XDR alerts.

A starting query

Device code sign-ins in the last day:

SigninLogs
| where TimeGenerated > ago(1d)
| where AuthenticationProtocol == "deviceCode"
| project TimeGenerated, UserPrincipalName, AppDisplayName, IPAddress, Location, ResultType, DeviceDetail

Users outside an approved list:

let approved = dynamic(["[email protected]", "[email protected]"]);
SigninLogs
| where AuthenticationProtocol == "deviceCode" and ResultType == "0"
| where UserPrincipalName !in~ (approved)
| summarize Count = count(), IPs = make_set(IPAddress) by UserPrincipalName

Response

  1. Revoke sessions and refresh tokens for affected users.
  2. Review mailbox and file activity after the sign-in.
  3. Remove malicious inbox rules and OAuth consents.
  4. Block device code flow with Conditional Access.

Sources

  1. Source
detect device code phishingEvilTokens device code phishing2026

More on this story