Welcome to our Tech Tip of the Month! Each month, we share practical tech advice to help you work smarter, stay secure, and get more out of your tools.
Security Spotlight: Beware of Device Code Phishing
Cybercriminals are constantly finding new ways to bypass security measures, and one growing threat is device code phishing.
This attack occurs when a scammer tricks a user into entering a code, such as ABC123, into a legitimate Microsoft sign-in page. While the website is genuine, the code is linked to the attacker’s device. By entering the code and completing the sign-in process, you may unknowingly grant the attacker access to your account on their device.
What makes this attack particularly concerning is that it can bypass certain security controls. In some cases, the trust associated with a company-managed device can be transferred through the authentication process, allowing attackers to gain access even when device-based security policies are in place.
How to stay safe:
- Never enter a device code unless you initiated the sign-in process yourself.
- Be cautious of unexpected requests via email, Teams, phone calls, or text messages.
- If you’re unsure, contact your IT provider before proceeding.
To further protect our clients, we have started rolling out a policy that blocks device code authentication for all users except approved accounts where this functionality is required. This change reduces the risk of device code phishing and strengthens the security of client environments against this increasingly common attack method.
Staying alert and verifying unexpected requests remains one of the best defenses against modern phishing attacks. By understanding how these attacks work, users can help keep both their accounts and their organisation secure.
We hope you find this helpful! Stay tuned for more tech tips next month where we’ll share more practical ways to boost productivity and stay secure. Happy computing!


