Skip to content
Blocking Device Code Flows DCF in Microsoft Entra ID to Protect your Tenant from Phishing Attacks

Blocking Device Code Flows DCF in Microsoft Entra ID to Protect your Tenant from Phishing Attacks

Written By Anoop C Nair
Last Updated February 18, 2025
Posted In Entra
SHARE

Hey there, Let’s discuss about “Blocking Device Code Flows DCF in Microsoft Entra ID to Protect your Tenant from Phishing Attacks”. Microsoft Threat Intelligence has recently reported that the threat actor known as Storm-2372, a Russia-aligned actor interests, has been actively employing Device Code Flow (DCF) techniques to organise and implement complex phishing campaigns.

The attacks utilize a phishing technique known as “device code phishing,” which tricks users into logging into productivity apps while the Storm-2372 actors capture information from the login (tokens) to access compromised accounts.

The attacks have been ongoing since August 2024, targeting governments, NGOs, and various industries across multiple regions. Microsoft Threat Intelligence Center continues to track campaigns launched by Storm-2372. Microsoft’s Threat Intelligence Center actively monitors campaigns by Storm-2372 and notifies customers targeted or compromised when possible, providing necessary information.

When possible, they directly notify customers who have been targeted, providing them with the necessary information. To overcome this, Microsoft recommends blocking device code flow wherever possible and only allowing device code flow where necessary.

Patch My PC

What is Device Code Flow?

Device code flow is used to log in to devices lacking local input options, such as shared devices or digital signage displays.

Blocking Device Code Flows DCF in Microsoft Entra ID to Protect your Tenant from Phishing Attacks

Microsoft has noted that Storm-2372 has transitioned to using the specific client ID for the Microsoft Authentication Broker in the device code sign-in process. Here we are discussing about the topic Device Code Flow Under Threats Targeting Various Industries and Regions.

Blocking Device Code Flows DCF in Microsoft Entra ID to Protect your Tenant from Phishing Attacks - Fig.1
Blocking Device Code Flows DCF in Microsoft Entra ID to Protect your Tenant from Phishing Attacks – Fig.1

To get out from this threat Microsoft’s recommendation is to block device code flow wherever possible and only allow device code flow where necessary.

Solution for the Threat
Block device code flow
Blocking Device Code Flows DCF in Microsoft Entra ID to Protect your Tenant from Phishing Attacks – Table.1

Attack Cycle of Device Code Phishing

During the attack, the threat actor creates a legitimate device code request to tricks the target into entering it on a valid sign-in page. This allows the actor access and enables them to capture the authentication access. We will get a clear picture from the below screenshot.

Device Code Flow Under Threats Targeting Various Industries and Regions - Fig.2 Creds-MS
Blocking Device Code Flows DCF in Microsoft Entra ID to Protect your Tenant from Phishing Attacks – Fig.2 Creds-MS

Block Device Code Flow

Restrict the device code flow using Microsoft Entra’s conditional access policies. Sign in to the Microsoft Entra admin center and navigate Protection > Conditional Access > Policies. Specifically, we can block the device code flow by configuring the Authentication Flows condition in your policies, which allows you to control who can use it in your environment.

Blocking Device Code Flows DCF in Microsoft Entra ID to Protect your Tenant from Phishing Attacks - Fig.3
Blocking Device Code Flows DCF in Microsoft Entra ID to Protect your Tenant from Phishing Attacks – Fig.3

Need Further Assistance or Have Technical Questions?

Join theLinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Resource

LinkedIn post of Merill Fernando

Author

Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Entra

Entra ID SSPR Improves Security with Registered Authentication Methods | Impact on Unregistered Users Starting September 2026

Key Takeaway Entra ID SSPR Improves Security with Registered Authentication Methods! Starting September 7, 2026, Microsoft Entra ID Self-Service Password Reset (SSPR) will require users to verify their identity using explicitly registered authentication methods. Directory-sourced contact information, such as mobile phone numbers, business phone numbers, and alternate email addresses, will no longer be accepted for […]

AC Anoop C Nair 4 min read
Entra

Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing

Key Takeaways Explicit Forward Proxy in Microsoft Entra Internet Access! This feature allows organizations to use secure web and AI gateway capabilities without deploying the Global Secure Access client, making it useful for browser-based and lightly managed environments. It works with browsers that support Proxy Auto-Configuration (PAC) files. Since this is a prerelease feature, Microsoft […]

AC Anoop C Nair 3 min read
Cloud

Microsoft Enables Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server

Key Takeaways: Let’s discuss about Microsoft Unlocks Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server. For customers with no remaining dependency on their last Exchange Server, a guide for decommissioning your last Exchange Server. Microsoft announced the Public Preview of Cloud-Managed Remote Mailboxes. Microsoft is excited to share these two new milestones […]

AC Anoop C Nair 3 min read