Device code phishing is a clever Microsoft 365 attack that can steal an authenticated session without stealing your password.** An attacker starts a login, sends you the device code, and tricks you into completing the sign-in on Microsoft's genuine website. Even MFA may not save you because you're unknowingly approving the attacker's session. The best defence is simple: **if you didn't start the login, don't finish it.