Hacker News new | ask | show | jobs
An AI‑enabled device code phishing campaign (microsoft.com)
2 points by buccal 43 days ago
1 comments

Microsoft leaves mitigation of this known and quite powerful phishing vector behind additional licensing requirements. You cannot reliably block Microsoft Entra device code flow without Entra ID Premium P1.

Password managers, FIDO keys will not help you as the authentication flow is happening in Microsoft servers.