
Techniques
Device Code Phishing: Skipping the Password, Registering the Device
An MFA bypass with no fake login page: the victim completes a real Microsoft sign-in, and the attacker walks away with a live session. Abusing the Authentication Broker client can turn that session into a registered device and a Primary Refresh Token.
8 min read
