All articles

Microsoft 365

#Microsoft 365

1 article

Techniques

Device Code Phishing: Skipping the Password, Registering the Device

An MFA bypass with no fake login page: the victim completes a real Microsoft sign-in, and the attacker walks away with a live session. Abusing the Authentication Broker client can turn that session into a registered device and a Primary Refresh Token.

8 min read